UNSOLVED

lutts

updated

16 years ago

L

lutts

28 Posts

0

3625

June 25th, 2010 11:00

Redirected search

When I tried to do a google search, I have been redirected to a different page. This occur only sometimes and when this happens, another unwanted window also opens up. Can someone please look into this log file and help me fix these errors. Thanks.

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:34:26 AM, on 6/25/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)


Boot mode: Normal

Running processes:
C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\RegGenie\RegGenieScheduler.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\OEM02Mon.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Fingerprint Reader Suite\psqltray.exe
C:\Windows\System32\wpcumi.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\1-Click Answers\answers.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Windows Live\Toolbar\wltuser.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Program Files\Dell Remote Access\ezi_ra.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\PROGRA~1\1-CLIC~1\agtserv.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
R3 - URLSearchHook: (no name) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
O4 - HKCU\..\Run: [googletalk] C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Jumblo] "C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe" -nosplash -minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Dell Remote Access.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O13 - Gopher Prefix:
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://mdev.temple.edu/webcams/AxisCamControl.ocx
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 14853 bytes

  • kevin27_b3d29f

    2 Intern

    1547 Posts

    425

    0

    Posted July 11th, 2010 02:00

    Hi lutts,

    Welcome to the Dell Community Malware Removal Froum.

    Sorry for the delay in getting to you.

    Due to the nature of malware and the last log that was posted, please post a fresh HJT log and the symptoms that still persist.

    Thanks,

    K27.

  • lutts

    28 Posts

    425

    0

    Posted July 12th, 2010 22:00

    Hello K27,

    Thank you for helping me out. When I tried to run another system scan and save a copy of the log file, I got a dialog box as follows:

    For some reason yoursystem denied write access to the Hosts file. If any hijacked domains are in this file, HiJackThis may not be able to fix this..........

    After I clicked ok, I got the log file shown below:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:34:26 AM, on 6/25/2010
    Platform: Windows Vista SP2 (WinNT 6.00.1906)
    MSIE: Internet Explorer v7.00 (7.00.6002.18005)
    Boot mode: Normal

    Running processes:
    C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files\RegGenie\RegGenieScheduler.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\DellTPad\Apoint.exe
    C:\Windows\OEM02Mon.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Windows\System32\mobsync.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Fingerprint Reader Suite\psqltray.exe
    C:\Windows\System32\wpcumi.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\1-Click Answers\answers.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\PROGRA~1\1-CLIC~1\agtserv.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\Windows\system32\SearchFilterHost.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
    R3 - URLSearchHook: (no name) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - (no file)
    O1 - Hosts: ::1 localhost
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
    O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
    O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\IPSBHO.DLL
    O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
    O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
    O3 - Toolbar: IndianTerminalLive Toolbar - {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - C:\Program Files\IndianTerminalLive\tbIndi.dll
    O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\coIEPlg.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [Apoint] C:\Program Files\DellTPad\Apoint.exe
    O4 - HKLM\..\Run: [OEM02Mon.exe] C:\Windows\OEM02Mon.exe
    O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Fingerprint Reader Suite\launcher.exe" /startup
    O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
    O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
    O4 - HKLM\..\Run: [Dell DataSafe Online] "C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe" /m
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NVHotkey] rundll32.exe C:\Windows\system32\nvHotkey.dll,Start
    O4 - HKLM\..\Run: [dellsupportcenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P dellsupportcenter
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
    O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
    O4 - HKLM\..\RunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
    O4 - HKLM\..\RunOnce: [Uninstall Adobe Download Manager] "C:\Windows\system32\rundll32.exe" "C:\Program Files\NOS\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    O4 - HKCU\..\Run: [googletalk] C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe /autostart
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Jumblo] "C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe" -nosplash -minimized
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
    O4 - Global Startup: 1-Click Answers.lnk = C:\Program Files\1-Click Answers\answers.exe
    O4 - Global Startup: Bluetooth.lnk = ?
    O4 - Global Startup: Dell Remote Access.lnk = ?
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: QuickSet.lnk = C:\Program Files\Dell\QuickSet\quickset.exe
    O8 - Extra context menu item: Answers... - file://C:\Program Files\1-Click Answers\Html\atiemenu.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Send image to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
    O8 - Extra context menu item: Send page to &Bluetooth Device... - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
    O13 - Gopher Prefix:
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
    O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://mdev.temple.edu/webcams/AxisCamControl.ocx
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
    O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll
    O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:\Windows\system32\aestsrv.exe
    O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
    O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    O23 - Service: Google Desktop Manager 5.9.911.3589 (GoogleDesktopManager-110309-193829) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
    O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    O23 - Service: Norton 360 (N360) - Symantec Corporation - C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    O23 - Service: SupportSoft Sprocket Service (DellSupportCenter) (sprtsvc_DellSupportCenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: SigmaTel Audio Service (STacSV) - IDT, Inc. - C:\Windows\system32\STacSV.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of file - 14853 bytes

     

    Symptoms: Redirected searches, a new problem popped up  in the past days. My disk crashes occasionally (a blue screen appears and then shut down the computer). More often, IE displays as not responding . Hope this will help. Thanks.

  • kevin27_b3d29f

    2 Intern

    1547 Posts

    425

    0

    Posted July 13th, 2010 14:00

    Hi lutts,

    Your Welcome. And the symptoms you described were a great help, Thank You.

    The message from HJT is because you are running Vista and as such you need to right click the program and then click Run as Administrator. Please also do this for all other programs I ask you to run, it will make things go a bit more smoothly.

    Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.

    Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.

    Please DO NOT use this system for anything apart from visiting this forum and other sites I direct you too, as this will only make the cleanup process all the more diffecult.

    I need to see some additional information about what is happening in your machine.
    Please perform the following scan:

    • Download DDS by sUBs from one of the following links. Save it to your desktop.
    • Double click on the DDS icon, allow it to run.
    • A small box will open, with an explanation about the tool.
    • When done, DDS will open two (2) logs
      1. DDS.txt
      2. Attach.txt
    • Save both reports to your desktop.
    • The instructions here ask you to attach the Attach.txt.
      DDS.jpg
    • Instead of attaching, please copy/past both logs into your next reply.
    • Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control here

     

    YOU MUST DISABLE ALL REAL TIME PROTECTION BEFORE RUNNING THE NEXT TOOL,

    Next, download this Antirootkit Program to a folder that you create such as C:\ARK, by choosing the "Download EXE" button on the webpage.

    Please Disable all Anti-virus/Anti-Spyware/FireWall on your machine(instructions via links below)

     

    Next, please perform a rootkit scan:

    • Double-click the randomly name EXE located in the C:\ARK folder that you just downloaded to launch it
    • When the program opens, it will automatically initiate a very fast scan of common rootkit hiding places.
    • When the "quick" scan is finished (a few seconds), click the Rootkit/Malware tab,and then select the Scan button.
    • Leave your system completely idle while this longer scan is in progress.
    • When the scan is done, save the scan log to the Windows clipboard
    • Open Notepad or a similar text editor
    • Paste the clipboard contents into a text file by clicking Edit | Paste or Ctl V
    • Exit the Program
    • Save the Scan log as ARK.txt and post it in your next reply.
    • Now, re-enable the active protection component of any antivirus/antimalware programs you disabled before performing the scan.


    .
    If the ARK tool crashes your machine or causes a Blue Screen error, please post the log results from the first inital quick scan,this can be saved in the same way as the full scan in the above instructions.

     

    Please COPY/PASTE BOTH DDS logs and the ARK log back to this thread,
    Thanks
    K27

  • kevin27_b3d29f

    2 Intern

    1547 Posts

    425

    0

    Posted July 15th, 2010 11:00

    Hi lutts,

    Do you still require assistance?

    Thanks.

  • lutts

    28 Posts

    425

    0

    Posted July 15th, 2010 14:00

    Hi K27,

    I really need your assistance. What happenned was, all this time I was expecting an e-mail from you but now only I realizedI I kinda overlooked your e-mail. My inbox is full of unwanted mails and your e-mail was buried in it. I am very sorry for the inconvenience. I was going to my usual websites as I didn`t read the instructions in ur e-mail. Do you want me to send a new HJT log?  I will post a new HJT log and post the other required things mentioned in your previous e-mail soon.  Sorry again for my late reply.

    Thanks,

    lutts

  • kevin27_b3d29f

    2 Intern

    1547 Posts

    425

    0

    Posted July 15th, 2010 22:00

    Hi lutts,

    Don't worry about the email thing, there seems to have been some sort of problem with it over the last few day's but I think it is getting better.

    There is no need to post a fresh HJT log yet. Please follow the instruction's in my last post for running DDS and the ARK tool.

    thanks,
    K27.

  • lutts

    28 Posts

    426

    0

    Posted July 16th, 2010 16:00

    Hey K27,

    I forgot to mention some symptoms in my earlier posts: I often get a message showing that Windows Host Services stopped working and the norton warns an intrusion attack and was resulted from DEVICE/HARDDISKVOLUME3/PROGRAMFILES/INTERNETEXPLORER/EXPLORER.EXE. Orsometime its shows the attack was resulted from SYSTEM32/SVCHOST.EXE something like that...

    Here is the DDS LOG:


    DDS (Ver_10-03-17.01) - NTFSx86 
    Run by APARNA at 12:21:20.25 on Fri 07/16/2010
    Internet Explorer: 7.0.6002.18005
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3069.1061 [GMT -4:00]

    SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\aestsrv.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Windows\system32\STacSV.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\DllHost.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\DellTPad\Apoint.exe
    C:\Windows\OEM02Mon.exe
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Windows\System32\wpcumi.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\1-Click Answers\answers.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Fingerprint Reader Suite\psqltray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\1-CLIC~1\agtserv.exe
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Users\APARNA\Downloads\dds.pif

    ============== Pseudo HJT Report ===============

    uSearch Page = hxxp://www.google.com
    uStart Page = www.yahoo.com
    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6090117
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
    uURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    uURLSearchHooks: H - No File
    mURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\norton 360\engine\4.2.0.12\IPSBHO.DLL
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
    uRun: [googletalk] c:\users\aparna\appdata\roaming\google\google talk\googletalk.exe /autostart
    uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [Jumblo] "c:\program files\jumblo.com\jumblo\Jumblo.exe" -nosplash -minimized
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [Apoint] c:\program files\delltpad\Apoint.exe
    mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
    mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
    mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
    mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
    mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
    mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    mRunOnce: [VistaSetup]
    mRunOnce: [*Restore] c:\windows\system32\rstrui.exe /runonce
    StartupFolder: c:\users\aparna\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\1-clic~1.lnk - c:\program files\1-click answers\answers.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellre~1.lnk - c:\windows\installer\{f66a31d9-7831-4fba-ba02-c411c0047cc5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: DisableCAD = 1 (0x1)
    IE: Answers... - file://c:\program files\1-click answers\html\atiemenu.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://mdev.temple.edu/webcams/AxisCamControl.ocx
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    Notify: psfus - c:\windows\system32\psqlpwd.dll
    AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    LSA: Notification Packages = scecli psqlpwd
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2010-7-5 42376]
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-11 328752]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-11 173104]
    R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-12 691248]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-11 501888]
    R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100715.001\IDSvix86.sys [2010-7-16 344112]
    R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2010-7-5 66952]
    R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2010-7-5 81288]
    R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2010-7-5 160648]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-11 116784]
    R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0402000.00c\symtdiv.sys [2010-6-11 339504]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2009-1-17 73728]
    R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-24 155648]
    R2 N360;Norton 360;c:\program files\norton 360\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-6-11 126392]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-6-11 1153368]
    R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-7-5 356920]
    R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-7-5 1073544]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-5 102448]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-19 135664]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-2-15 54632]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
    S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-1-17 30192]
    S4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2009-1-17 209408]

    =============== Created Last 30 ================

    2010-07-14 23:15:34 0 d-----w- c:\windows\system32\Adobe
    2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagwrn.xml
    2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagerr.xml
    2010-07-05 20:06:00 160648 ----a-w- c:\windows\system32\drivers\pctfw2.sys
    2010-07-05 20:05:52 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
    2010-07-05 20:05:51 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
    2010-07-05 20:05:51 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
    2010-07-05 20:05:51 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
    2010-07-05 20:05:33 0 d-----w- c:\users\aparna\appdata\roaming\PC Tools
    2010-07-05 20:05:33 0 d-----w- c:\programdata\PC Tools
    2010-07-05 19:13:33 767952 ----a-w- c:\windows\BDTSupport.dll.old
    2010-07-05 19:13:32 1652688 ----a-w- c:\windows\PCTBDCore.dll.old
    2010-07-05 19:09:53 0 d-----w- c:\program files\Spyware Doctor
    2010-07-05 19:09:53 0 d-----w- c:\program files\common files\PC Tools
    2010-06-25 15:33:50 0 d-----w- c:\program files\Trend Micro
    2010-06-18 20:51:01 0 d-----w- c:\programdata\HP Product Assistant

    ==================== Find3M  ====================

    2010-07-16 13:58:56 48158 ----a-w- c:\programdata\nvModes.dat
    2010-06-18 20:54:25 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstor.dat
    2010-06-11 16:24:01 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
    2010-06-11 16:24:01 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
    2010-06-11 16:24:01 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-06-11 16:20:40 145503112 ----a-w- c:\users\aparna\N360_2010_4.0_Build_127_OEM90_Microsoft.exe
    2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-02 13:42:25 8656832 ----a-w- c:\users\aparna\appdata\roaming\DataSafeDotNet.exe
    2010-04-28 07:00:59 67424 ----a-w- c:\windows\fonts\upcfi.ttf
    2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-02-15 19:34:56 665600 ----a-w- c:\windows\inf\drvindex.dat
    2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-01-17 21:02:56 75 --sha-r- c:\windows\CT4CET.bin
    2009-01-17 22:17:13 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 12:23:14.56 ===============

     

    Here is the ARK log:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-07-16 14:19:10
    Windows 6.0.6002 Service Pack 2
    Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT            92BF6120                                                                                                                                                ZwAlertResumeThread
    SSDT            92BF5120                                                                                                                                                ZwAlertThread
    SSDT            933D5940                                                                                                                                                ZwAllocateVirtualMemory
    SSDT            913F8C98                                                                                                                                                ZwAlpcConnectPort
    SSDT            92F70048                                                                                                                                                ZwAssignProcessToJobObject
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateKey [0x8FB1B7A6]
    SSDT            933DEFC0                                                                                                                                                ZwCreateMutant
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcess [0x8FB18794]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcessEx [0x8FB18F1E]
    SSDT            933E37B8                                                                                                                                                ZwCreateSymbolicLinkObject
    SSDT            933D7380                                                                                                                                                ZwCreateThread
    SSDT            92FBE048                                                                                                                                                ZwDebugActiveProcess
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteKey [0x8FB1C1F0]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteValueKey [0x8FB1C42A]
    SSDT            933D5B58                                                                                                                                                ZwDuplicateObject
    SSDT            933D7B30                                                                                                                                                ZwFreeVirtualMemory
    SSDT            92F93048                                                                                                                                                ZwImpersonateAnonymousToken
    SSDT            92F74048                                                                                                                                                ZwImpersonateThread
    SSDT            89C9F728                                                                                                                                                ZwLoadDriver
    SSDT            933D79D0                                                                                                                                                ZwMapViewOfSection
    SSDT            92F94048                                                                                                                                                ZwOpenEvent
    SSDT            933D5DB8                                                                                                                                                ZwOpenProcess
    SSDT            9182A118                                                                                                                                                ZwOpenProcessToken
    SSDT            92FA9048                                                                                                                                                ZwOpenSection
    SSDT            933D5CA8                                                                                                                                                ZwOpenThread
    SSDT            933E13F0                                                                                                                                                ZwProtectVirtualMemory
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwRenameKey [0x8FB1D12A]
    SSDT            9190F120                                                                                                                                                ZwResumeThread
    SSDT            91909108                                                                                                                                                ZwSetContextThread
    SSDT            933D77B8                                                                                                                                                ZwSetInformationProcess
    SSDT            92FBD048                                                                                                                                                ZwSetSystemInformation
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwSetValueKey [0x8FB1C83C]
    SSDT            92FA8048                                                                                                                                                ZwSuspendProcess
    SSDT            901F7120                                                                                                                                                ZwSuspendThread
    SSDT            91825108                                                                                                                                                ZwTerminateProcess
    SSDT            901F5118                                                                                                                                                ZwTerminateThread
    SSDT            91904118                                                                                                                                                ZwUnmapViewOfSection
    SSDT            933D7E40                                                                                                                                                ZwWriteVirtualMemory
    SSDT            933E2FB0                                                                                                                                                ZwCreateThreadEx
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateUserProcess [0x8FB196B6]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text           ntkrnlpa.exe!KeSetEvent + 11D                                                                                                                           81CED880 8 Bytes  [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 131                                                                                                                           81CED894 4 Bytes  [40, 59, 3D, 93]
    .text           ntkrnlpa.exe!KeSetEvent + 13D                                                                                                                           81CED8A0 4 Bytes  [98, 8C, 3F, 91]
    .text           ntkrnlpa.exe!KeSetEvent + 191                                                                                                                           81CED8F4 4 Bytes  [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 1E9                                                                                                                           81CED94C 4 Bytes  [A6, B7, B1, 8F]
    .text           ...                                                                                                                                                    
    ?               C:\Windows\system32\Drivers\mchInjDrv.sys                                                                                                               The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose                                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4                                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile                                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4                                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey                                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4                                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess                                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4                                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx                                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4                                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection                                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4                                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey                                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4                                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey                                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4                                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey                                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4                                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile                                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4                                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey                                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4                                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess                                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4                                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile                                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4                                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather                                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4                                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory                                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4                                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess                                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4                                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW                                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA                                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW                                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 0028000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 0029000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0027000A
    .text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance                                                                                        76709EA6 5 Bytes  JMP 007C000A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos                                                                                           77B60B88 5 Bytes  JMP 012E000A
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4                                                  77A74318 2 Bytes  [35, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4                                              77A74418 2 Bytes  [05, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4                                          77A74498 2 Bytes  [29, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4                                          77A744C8 2 Bytes  [23, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4                                              77A747C8 2 Bytes  [0B, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4                                         77A747F8 2 Bytes  [11, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4                                     77A752E8 2 Bytes  [20, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4                                              77A75648 2 Bytes  [1A, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4                                        77A75658 2 Bytes  [1D, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4                                     77A75678 2 Bytes  [32, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4                                      77A75808 2 Bytes  [26, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory                                                                                          77A74D34 5 Bytes  JMP 0083000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 5 Bytes  JMP 0084000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher                                                                                       77A75DC8 5 Bytes  JMP 0082000A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A                                                                        7661C928 4 Bytes  CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW                                                            77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory                                                                  77A74D34 5 Bytes  JMP 0023000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 5 Bytes  JMP 0024000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher                                                               77A75DC8 5 Bytes  JMP 0022000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW                                                                        77B710B0 5 Bytes  JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW                                                                77B72EF5 5 Bytes  JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA                                                                        77B88152 5 Bytes  JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA                                                                77B8847D 5 Bytes  JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA                                                                    77B9D4D9 5 Bytes  JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW                                                                    77B9D5D3 5 Bytes  JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA                                                                          77B9D639 5 Bytes  JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW                                                                          77B9D65D 5 Bytes  JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D                                                                    76F88910 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25                                                                    76F88918 4 Bytes  [A7, 0A, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95                                                                    76F88988 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D                                                                    76F88990 8 Bytes  [A7, 0A, BE, 63, A4, 32, BD, ...]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream                                                                       766D1E12 5 Bytes  JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose                                                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4                                                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile                                                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4                                                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey                                                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4                                                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess                                                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4                                                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx                                                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4                                                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection                                                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4                                                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey                                                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4                                                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey                                                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4                                                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey                                                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4                                                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile                                                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4                                                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey                                                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4                                                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess                                                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4                                                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile                                                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4                                                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather                                                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4                                                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4                                                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess                                                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4                                                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW                                                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose                                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4                                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile                                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4                                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey                                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4                                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess                                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4                                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx                                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4                                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection                                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4                                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey                                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4                                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey                                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4                                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey                                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4                                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile                                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4                                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey                                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4                                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess                                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4                                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile                                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4                                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather                                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4                                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory                                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4                                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess                                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4                                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW                                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA                                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW                                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A                                                                       7661C928 4 Bytes  CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F040F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F0A0F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose                                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4                                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile                                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4                                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey                                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4                                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess                                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4                                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx                                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4                                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection                                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4                                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey                                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4                                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey                                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4                                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey                                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4                                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile                                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4                                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey                                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4                                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess                                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4                                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile                                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4                                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather                                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4                                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory                                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4                                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess                                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4                                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW                                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA                                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW                                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 006A000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 006B000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0069000A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose                                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4                                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile                                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4                                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey                                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4                                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess                                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4                                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx                                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4                                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection                                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4                                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey                                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4                                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey                                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4                                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey                                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4                                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile                                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4                                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey                                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4                                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess                                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4                                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile                                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4                                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather                                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4                                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory                                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4                                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess                                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4                                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW                                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA                                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW                                                                            77B487AD 6 Bytes  JMP 5F3B0F5A

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap]          00C0E660
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]          00C0E140
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle]         00C0D2A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent]       00C0EBE0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread]            00C0C260
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]          00C0BBD0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW]  00C0BF90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer]          00C0D100
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx]         00C0D7C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW]      00C0D550
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile]           00C0D740
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW]        00C0DC20
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile]         00C0D930
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType]             00C0D450
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile]         00C0D690
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize]             00C0D240
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile]               00C0D0C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP]                  00C0E680
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess]        00C0C110
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc]             00C0E3A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock]              00C0E2C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock]            00C0E280
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]             00C0C940
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]            00C0BA30
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle]             00C0D340
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]            00C0B9A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary]             00C0BC80
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress]          00C0A730
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile]                00C0CC90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion]              00C0E650
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW]                 00C0E920
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW]               00C0E8C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW]        00C0EB10
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW]           00C0EBB0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW]               00C0E9E0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]          00C0E5D0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]         00C0E580
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                                   [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                                    [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                                [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                          [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                                    [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                                 [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                                     [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                                        [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                                [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                                 [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                                  [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                          [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                             [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                                [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                          [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                         [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                            [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                          [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                                       [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                    [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW]                                         [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                        [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                          [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                  [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW]                                     [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW]                                     [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW]                                  [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW]                                     [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW]                                   [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey]                                       [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA]                                    [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA]                                     [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA]                                [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA]                              [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA]                                [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA]                                  [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA]                                  [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA]                                       [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW]                                [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW]                                [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW]                                  [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW]                                  [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA]                                         [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA]                                       [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                         [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                               [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                                      [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                                   [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                                    [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                                      [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA]                                           [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA]                                  [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA]                                    [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA]                                    [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA]                                    [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA]                                      [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                        [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]                   [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]                      [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                                  [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW]                             [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                        [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                                   [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                        [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                                [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                            [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW]                                 [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW]                                 [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                                      [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW]                                [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW]                             [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW]                                 [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                         [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                               [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW]                                     [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW]                                      [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW]                                    [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                                [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose]                                          [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]                                     [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW]                                  [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW]                               [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW]                                 [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW]                                       [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]                                     [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW]                                      [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW]                                      [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA]                                        [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA]                                      [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                   [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                   [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW]                                     [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW]                                        [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey]                                        [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW]                                   [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW]                                      [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW]                                      [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]                                    [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA]                                   [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA]                                      [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                    [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                      [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                                    [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                      [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                   [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                     [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                     [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                                   [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject]                                      [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx]                                  [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu]                                    [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush]                                  [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow]                                     [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\RawIp                                                                                                                               pctfw2.sys
    AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                                fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39                                                                            
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                0x9B 0x4D 0xE1 0x7E ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)                                                        
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                    0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                    0x9B 0x4D 0xE1 0x7E ...

    ---- EOF - GMER 1.0.15 ----

  • lutts

    28 Posts

    426

    0

    Posted July 16th, 2010 16:00

    Hey K27,

    I forgot to mention some symptoms in my earlier posts: I often get a message showing that Windows Host Services stopped working and the norton warns an intrusion attack and was resulted from DEVICE/HARDDISKVOLUME3/PROGRAMFILES/INTERNETEXPLORER/EXPLORER.EXE. Orsometime its shows the attack was resulted from SYSTEM32/SVCHOST.EXE something like that...

    Here is the DDS LOG:


    DDS (Ver_10-03-17.01) - NTFSx86 
    Run by APARNA at 12:21:20.25 on Fri 07/16/2010
    Internet Explorer: 7.0.6002.18005
    Microsoft® Windows Vista™ Home Premium   6.0.6002.2.1252.1.1033.18.3069.1061 [GMT -4:00]

    SP: Spybot - Search and Destroy *enabled* (Outdated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
    SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}

    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k rpcss
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\SLsvc.exe
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\nvvsvc.exe
    C:\Program Files\Dell\DellDock\DockLogin.exe
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Fingerprint Reader Suite\upeksvr.exe
    C:\Windows\system32\WLANExt.exe
    C:\Windows\System32\spoolsv.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    C:\Windows\system32\aestsrv.exe
    C:\Windows\system32\svchost.exe -k bthsvcs
    C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
    c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\svchost.exe -k hpdevmgmt
    C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
    C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
    C:\Program Files\Spyware Doctor\pctsAuxs.exe
    C:\Program Files\Spyware Doctor\pctsSvc.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
    C:\Windows\system32\STacSV.exe
    C:\Windows\system32\svchost.exe -k imgsvc
    C:\Windows\System32\svchost.exe -k WerSvcGroup
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
    C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Windows\system32\DllHost.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\Program Files\DellTPad\Apoint.exe
    C:\Windows\OEM02Mon.exe
    C:\Program Files\Dell\DellDock\DellDock.exe
    C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
    C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
    C:\Program Files\Dell\MediaDirect\PCMService.exe
    C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe
    C:\Windows\System32\rundll32.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
    C:\Windows\System32\wpcumi.exe
    C:\Program Files\Spyware Doctor\pctsTray.exe
    C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe
    C:\Program Files\Windows Live\Messenger\msnmsgr.exe
    C:\Windows\system32\wuauclt.exe
    C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\Program Files\1-Click Answers\answers.exe
    C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
    C:\Program Files\Dell Remote Access\ezi_ra.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Dell\QuickSet\quickset.exe
    C:\Program Files\Fingerprint Reader Suite\psqltray.exe
    C:\Windows\system32\wbem\wmiprvse.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
    C:\Program Files\Internet Explorer\ieuser.exe
    C:\Program Files\DellTPad\ApMsgFwd.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\PROGRA~1\1-CLIC~1\agtserv.exe
    C:\Program Files\Windows Live\Toolbar\wltuser.exe
    C:\Program Files\DellTPad\Apntex.exe
    C:\Program Files\DellTPad\HidFind.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe
    C:\Windows\System32\svchost.exe -k HPZ12
    C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe
    C:\Windows\servicing\TrustedInstaller.exe
    C:\Users\APARNA\Downloads\dds.pif

    ============== Pseudo HJT Report ===============

    uSearch Page = hxxp://www.google.com
    uStart Page = www.yahoo.com
    uWindow Title = Internet Explorer provided by Dell
    uDefault_Page_URL = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=6090117
    uSearch Bar = hxxp://www.google.com/ie
    uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
    uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
    uURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    uURLSearchHooks: H - No File
    mURLSearchHooks: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Symantec NCO BHO: {602adb0e-4aff-4217-8aa1-95dac4dfa408} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
    BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton 360\norton 360\engine\4.2.0.12\IPSBHO.DLL
    BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
    BHO: Groove GFS Browser Helper: {72853161-30c5-4d22-b7f9-0bbc1d38a37e} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    BHO: SSVHelper Class: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre1.6.0_07\bin\ssv.dll
    BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
    BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
    BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn0\YTSingleInstance.dll
    TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
    TB: IndianTerminalLive Toolbar: {2b406a81-8a44-4f80-b175-ca4e0d24a7c9} - c:\program files\indianterminallive\tbIndi.dll
    TB: Norton Toolbar: {7febefe3-6b19-4349-98d2-ffb09d4b49ca} - c:\program files\norton 360\norton 360\engine\4.2.0.12\coIEPlg.dll
    TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn0\yt.dll
    TB: {472734EA-242A-422B-ADF8-83D1E48CC825} - No File
    uRun: [googletalk] c:\users\aparna\appdata\roaming\google\google talk\googletalk.exe /autostart
    uRun: [Messenger (Yahoo!)] "c:\progra~1\yahoo!\messenger\YahooMessenger.exe" -quiet
    uRun: [msnmsgr] "c:\program files\windows live\messenger\msnmsgr.exe" /background
    uRun: [Jumblo] "c:\program files\jumblo.com\jumblo\Jumblo.exe" -nosplash -minimized
    uRun: [WMPNSCFG] c:\program files\windows media player\WMPNSCFG.exe
    uRun: [SpybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe
    mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    mRun: [Apoint] c:\program files\delltpad\Apoint.exe
    mRun: [OEM02Mon.exe] c:\windows\OEM02Mon.exe
    mRun: [PSQLLauncher] "c:\program files\fingerprint reader suite\launcher.exe" /startup
    mRun: [IAAnotif] "c:\program files\intel\intel matrix storage manager\Iaanotif.exe"
    mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
    mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
    mRun: [Dell DataSafe Online] "c:\program files\dell datasafe online\DataSafeOnline.exe" /m
    mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun: [NVHotkey] rundll32.exe c:\windows\system32\nvHotkey.dll,Start
    mRun: [dellsupportcenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P dellsupportcenter
    mRun: [GrooveMonitor] "c:\program files\microsoft office\office12\GrooveMonitor.exe"
    mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
    mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe
    mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
    mRun: [WPCUMI] c:\windows\system32\WpcUmi.exe
    mRun: [ISTray] "c:\program files\spyware doctor\pctsTray.exe"
    mRunOnce: [*WerKernelReporting] %SYSTEMROOT%\SYSTEM32\WerFault.exe -k -rq
    mRunOnce: [Uninstall Adobe Download Manager] "c:\windows\system32\rundll32.exe" "c:\program files\nos\bin\getPlus_Helper.dll",Uninstall /IE2883E8F-472F-4fb0-9522-AC9BF37916A7 /Get1noarp
    mRunOnce: [VistaSetup]
    mRunOnce: [*Restore] c:\windows\system32\rstrui.exe /runonce
    StartupFolder: c:\users\aparna\appdata\roaming\micros~1\windows\startm~1\programs\startup\delldo~1.lnk - c:\program files\dell\delldock\DellDock.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\1-clic~1.lnk - c:\program files\1-click answers\answers.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellre~1.lnk - c:\windows\installer\{f66a31d9-7831-4fba-ba02-c411c0047cc5}\NewShortcut10_F66A31D978314FBABA02C411C0047CC5.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe
    StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe
    mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    mPolicies-system: DisableCAD = 1 (0x1)
    IE: Answers... - file://c:\program files\1-click answers\html\atiemenu.htm
    IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
    IE: Send image to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm
    IE: Send page to &Bluetooth Device... - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm
    IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC} - c:\progra~1\java\jre16~1.0_0\bin\ssv.dll
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
    IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
    IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
    DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
    DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.5.4.cab
    DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} - hxxps://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
    DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} - hxxp://mdev.temple.edu/webcams/AxisCamControl.ocx
    DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
    DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - c:\program files\microsoft office\office12\GrooveSystemServices.dll
    Notify: GoToAssist - c:\program files\citrix\gotoassist\514\G2AWinLogon.dll
    Notify: psfus - c:\windows\system32\psqlpwd.dll
    AppInit_DLLs: c:\progra~1\google\google~3\GOEC62~1.DLL
    SEH: Groove GFS Stub Execution Hook: {b5a7f190-dda6-4420-b3ba-52453494e6cd} - c:\program files\microsoft office\office12\GrooveShellExtensions.dll
    LSA: Notification Packages = scecli psqlpwd
    Hosts: 127.0.0.1 www.spywareinfo.com

    ============= SERVICES / DRIVERS ===============

    R0 IKFileSec;File Security Driver;c:\windows\system32\drivers\ikfilesec.sys [2010-7-5 42376]
    R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\n360\0402000.00c\symds.sys [2010-6-11 328752]
    R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\n360\0402000.00c\symefa.sys [2010-6-11 173104]
    R1 BHDrvx86;BHDrvx86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\bashdefs\20100709.001\BHDrvx86.sys [2010-7-12 691248]
    R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\n360\0402000.00c\cchpx86.sys [2010-6-11 501888]
    R1 IDSVix86;IDSVix86;c:\programdata\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\n360_4.0.0.127\definitions\ipsdefs\20100715.001\IDSvix86.sys [2010-7-16 344112]
    R1 IKSysFlt;System Filter Driver;c:\windows\system32\drivers\iksysflt.sys [2010-7-5 66952]
    R1 IKSysSec;System Security Driver;c:\windows\system32\drivers\iksyssec.sys [2010-7-5 81288]
    R1 pctfw2;pctfw2;c:\windows\system32\drivers\pctfw2.sys [2010-7-5 160648]
    R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\n360\0402000.00c\ironx86.sys [2010-6-11 116784]
    R1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\system32\drivers\n360\0402000.00c\symtdiv.sys [2010-6-11 339504]
    R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2009-1-17 73728]
    R2 DockLoginService;Dock Login Service;c:\program files\dell\delldock\DockLogin.exe [2008-9-24 155648]
    R2 N360;Norton 360;c:\program files\norton 360\norton 360\engine\4.2.0.12\ccsvchst.exe [2010-6-11 126392]
    R2 SBSDWSCService;SBSD Security Center Service;c:\program files\spybot - search & destroy\SDWinSec.exe [2010-6-11 1153368]
    R2 sdAuxService;PC Tools Auxiliary Service;c:\program files\spyware doctor\pctsAuxs.exe [2010-7-5 356920]
    R2 sdCoreService;PC Tools Security Service;c:\program files\spyware doctor\pctsSvc.exe [2010-7-5 1073544]
    R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2010-7-5 102448]
    S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-19 135664]
    S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 21504]
    S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-2-15 54632]
    S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
    S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2009-1-17 30192]
    S4 iaNvStor;Intel(R) Turbo Memory Controller;c:\windows\system32\drivers\iaNvStor.sys [2009-1-17 209408]

    =============== Created Last 30 ================

    2010-07-14 23:15:34 0 d-----w- c:\windows\system32\Adobe
    2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagwrn.xml
    2010-07-05 23:10:23 1905 ----a-w- c:\windows\diagerr.xml
    2010-07-05 20:06:00 160648 ----a-w- c:\windows\system32\drivers\pctfw2.sys
    2010-07-05 20:05:52 29576 ----a-w- c:\windows\system32\drivers\kcom.sys
    2010-07-05 20:05:51 81288 ----a-w- c:\windows\system32\drivers\iksyssec.sys
    2010-07-05 20:05:51 66952 ----a-w- c:\windows\system32\drivers\iksysflt.sys
    2010-07-05 20:05:51 42376 ----a-w- c:\windows\system32\drivers\ikfilesec.sys
    2010-07-05 20:05:33 0 d-----w- c:\users\aparna\appdata\roaming\PC Tools
    2010-07-05 20:05:33 0 d-----w- c:\programdata\PC Tools
    2010-07-05 19:13:33 767952 ----a-w- c:\windows\BDTSupport.dll.old
    2010-07-05 19:13:32 1652688 ----a-w- c:\windows\PCTBDCore.dll.old
    2010-07-05 19:09:53 0 d-----w- c:\program files\Spyware Doctor
    2010-07-05 19:09:53 0 d-----w- c:\program files\common files\PC Tools
    2010-06-25 15:33:50 0 d-----w- c:\program files\Trend Micro
    2010-06-18 20:51:01 0 d-----w- c:\programdata\HP Product Assistant

    ==================== Find3M  ====================

    2010-07-16 13:58:56 48158 ----a-w- c:\programdata\nvModes.dat
    2010-06-18 20:54:25 51200 ----a-w- c:\windows\inf\infpub.dat
    2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstrng.dat
    2010-06-18 20:54:25 143360 ----a-w- c:\windows\inf\infstor.dat
    2010-06-11 16:24:01 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
    2010-06-11 16:24:01 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
    2010-06-11 16:24:01 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
    2010-06-11 16:20:40 145503112 ----a-w- c:\users\aparna\N360_2010_4.0_Build_127_OEM90_Microsoft.exe
    2010-05-21 18:14:28 221568 ------w- c:\windows\system32\MpSigStub.exe
    2010-05-02 13:42:25 8656832 ----a-w- c:\users\aparna\appdata\roaming\DataSafeDotNet.exe
    2010-04-28 07:00:59 67424 ----a-w- c:\windows\fonts\upcfi.ttf
    2010-04-23 14:13:55 2048 ----a-w- c:\windows\system32\tzres.dll
    2010-02-15 19:34:56 665600 ----a-w- c:\windows\inf\drvindex.dat
    2008-01-21 02:43:21 174 --sha-w- c:\program files\desktop.ini
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfd.dat
    2006-11-02 12:42:02 30674 ----a-w- c:\windows\inf\perflib\0409\perfc.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfi.dat
    2006-11-02 12:42:02 287440 ----a-w- c:\windows\inf\perflib\0409\perfh.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfi.dat
    2006-11-02 09:20:21 287440 ----a-w- c:\windows\inf\perflib\0000\perfh.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfd.dat
    2006-11-02 09:20:19 30674 ----a-w- c:\windows\inf\perflib\0000\perfc.dat
    2009-01-17 21:02:56 75 --sha-r- c:\windows\CT4CET.bin
    2009-01-17 22:17:13 8192 --sha-w- c:\windows\users\default\NTUSER.DAT

    ============= FINISH: 12:23:14.56 ===============

     

    Here is the ARK log:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-07-16 14:19:10
    Windows 6.0.6002 Service Pack 2
    Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT            92BF6120                                                                                                                                                ZwAlertResumeThread
    SSDT            92BF5120                                                                                                                                                ZwAlertThread
    SSDT            933D5940                                                                                                                                                ZwAllocateVirtualMemory
    SSDT            913F8C98                                                                                                                                                ZwAlpcConnectPort
    SSDT            92F70048                                                                                                                                                ZwAssignProcessToJobObject
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateKey [0x8FB1B7A6]
    SSDT            933DEFC0                                                                                                                                                ZwCreateMutant
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcess [0x8FB18794]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcessEx [0x8FB18F1E]
    SSDT            933E37B8                                                                                                                                                ZwCreateSymbolicLinkObject
    SSDT            933D7380                                                                                                                                                ZwCreateThread
    SSDT            92FBE048                                                                                                                                                ZwDebugActiveProcess
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteKey [0x8FB1C1F0]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteValueKey [0x8FB1C42A]
    SSDT            933D5B58                                                                                                                                                ZwDuplicateObject
    SSDT            933D7B30                                                                                                                                                ZwFreeVirtualMemory
    SSDT            92F93048                                                                                                                                                ZwImpersonateAnonymousToken
    SSDT            92F74048                                                                                                                                                ZwImpersonateThread
    SSDT            89C9F728                                                                                                                                                ZwLoadDriver
    SSDT            933D79D0                                                                                                                                                ZwMapViewOfSection
    SSDT            92F94048                                                                                                                                                ZwOpenEvent
    SSDT            933D5DB8                                                                                                                                                ZwOpenProcess
    SSDT            9182A118                                                                                                                                                ZwOpenProcessToken
    SSDT            92FA9048                                                                                                                                                ZwOpenSection
    SSDT            933D5CA8                                                                                                                                                ZwOpenThread
    SSDT            933E13F0                                                                                                                                                ZwProtectVirtualMemory
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwRenameKey [0x8FB1D12A]
    SSDT            9190F120                                                                                                                                                ZwResumeThread
    SSDT            91909108                                                                                                                                                ZwSetContextThread
    SSDT            933D77B8                                                                                                                                                ZwSetInformationProcess
    SSDT            92FBD048                                                                                                                                                ZwSetSystemInformation
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwSetValueKey [0x8FB1C83C]
    SSDT            92FA8048                                                                                                                                                ZwSuspendProcess
    SSDT            901F7120                                                                                                                                                ZwSuspendThread
    SSDT            91825108                                                                                                                                                ZwTerminateProcess
    SSDT            901F5118                                                                                                                                                ZwTerminateThread
    SSDT            91904118                                                                                                                                                ZwUnmapViewOfSection
    SSDT            933D7E40                                                                                                                                                ZwWriteVirtualMemory
    SSDT            933E2FB0                                                                                                                                                ZwCreateThreadEx
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateUserProcess [0x8FB196B6]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text           ntkrnlpa.exe!KeSetEvent + 11D                                                                                                                           81CED880 8 Bytes  [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 131                                                                                                                           81CED894 4 Bytes  [40, 59, 3D, 93]
    .text           ntkrnlpa.exe!KeSetEvent + 13D                                                                                                                           81CED8A0 4 Bytes  [98, 8C, 3F, 91]
    .text           ntkrnlpa.exe!KeSetEvent + 191                                                                                                                           81CED8F4 4 Bytes  [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 1E9                                                                                                                           81CED94C 4 Bytes  [A6, B7, B1, 8F]
    .text           ...                                                                                                                                                    
    ?               C:\Windows\system32\Drivers\mchInjDrv.sys                                                                                                               The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose                                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4                                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile                                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4                                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey                                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4                                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess                                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4                                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx                                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4                                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection                                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4                                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey                                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4                                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey                                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4                                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey                                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4                                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile                                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4                                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey                                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4                                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess                                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4                                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile                                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4                                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather                                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4                                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory                                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4                                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess                                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4                                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW                                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA                                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW                                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 0028000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 0029000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0027000A
    .text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance                                                                                        76709EA6 5 Bytes  JMP 007C000A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos                                                                                           77B60B88 5 Bytes  JMP 012E000A
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4                                                  77A74318 2 Bytes  [35, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4                                              77A74418 2 Bytes  [05, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4                                          77A74498 2 Bytes  [29, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4                                          77A744C8 2 Bytes  [23, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4                                              77A747C8 2 Bytes  [0B, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4                                         77A747F8 2 Bytes  [11, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4                                     77A752E8 2 Bytes  [20, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4                                              77A75648 2 Bytes  [1A, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4                                        77A75658 2 Bytes  [1D, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4                                     77A75678 2 Bytes  [32, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4                                      77A75808 2 Bytes  [26, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory                                                                                          77A74D34 5 Bytes  JMP 0083000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 5 Bytes  JMP 0084000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher                                                                                       77A75DC8 5 Bytes  JMP 0082000A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A                                                                        7661C928 4 Bytes  CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW                                                            77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory                                                                  77A74D34 5 Bytes  JMP 0023000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 5 Bytes  JMP 0024000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher                                                               77A75DC8 5 Bytes  JMP 0022000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW                                                                        77B710B0 5 Bytes  JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW                                                                77B72EF5 5 Bytes  JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA                                                                        77B88152 5 Bytes  JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA                                                                77B8847D 5 Bytes  JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA                                                                    77B9D4D9 5 Bytes  JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW                                                                    77B9D5D3 5 Bytes  JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA                                                                          77B9D639 5 Bytes  JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW                                                                          77B9D65D 5 Bytes  JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D                                                                    76F88910 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25                                                                    76F88918 4 Bytes  [A7, 0A, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95                                                                    76F88988 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D                                                                    76F88990 8 Bytes  [A7, 0A, BE, 63, A4, 32, BD, ...]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream                                                                       766D1E12 5 Bytes  JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose                                                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4                                                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile                                                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4                                                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey                                                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4                                                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess                                                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4                                                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx                                                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4                                                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection                                                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4                                                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey                                                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4                                                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey                                                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4                                                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey                                                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4                                                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile                                                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4                                                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey                                                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4                                                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess                                                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4                                                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile                                                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4                                                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather                                                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4                                                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4                                                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess                                                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4                                                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW                                                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose                                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4                                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile                                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4                                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey                                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4                                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess                                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4                                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx                                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4                                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection                                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4                                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey                                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4                                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey                                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4                                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey                                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4                                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile                                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4                                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey                                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4                                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess                                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4                                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile                                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4                                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather                                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4                                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory                                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4                                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess                                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4                                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW                                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA                                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW                                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A                                                                       7661C928 4 Bytes  CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F040F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F0A0F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose                                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4                                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile                                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4                                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey                                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4                                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess                                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4                                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx                                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4                                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection                                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4                                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey                                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4                                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey                                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4                                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey                                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4                                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile                                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4                                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey                                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4                                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess                                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4                                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile                                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4                                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather                                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4                                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory                                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4                                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess                                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4                                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW                                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA                                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW                                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 006A000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 006B000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0069000A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose                                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4                                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile                                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4                                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey                                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4                                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess                                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4                                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx                                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4                                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection                                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4                                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey                                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4                                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey                                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4                                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey                                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4                                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile                                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4                                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey                                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4                                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess                                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4                                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile                                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4                                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather                                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4                                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory                                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4                                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess                                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4                                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW                                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA                                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW                                                                            77B487AD 6 Bytes  JMP 5F3B0F5A

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap]          00C0E660
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]          00C0E140
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle]         00C0D2A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent]       00C0EBE0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread]            00C0C260
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]          00C0BBD0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW]  00C0BF90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer]          00C0D100
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx]         00C0D7C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW]      00C0D550
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile]           00C0D740
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW]        00C0DC20
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile]         00C0D930
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType]             00C0D450
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile]         00C0D690
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize]             00C0D240
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile]               00C0D0C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP]                  00C0E680
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess]        00C0C110
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc]             00C0E3A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock]              00C0E2C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock]            00C0E280
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]             00C0C940
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]            00C0BA30
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle]             00C0D340
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]            00C0B9A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary]             00C0BC80
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress]          00C0A730
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile]                00C0CC90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion]              00C0E650
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW]                 00C0E920
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW]               00C0E8C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW]        00C0EB10
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW]           00C0EBB0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW]               00C0E9E0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]          00C0E5D0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]         00C0E580
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                                   [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                                    [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                                [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                          [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                                    [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                                 [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                                     [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                                        [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                                [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                                 [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                                  [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                          [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                             [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                                [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                          [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                         [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                            [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                          [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                                       [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                    [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW]                                         [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                        [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                          [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                  [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW]                                     [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW]                                     [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW]                                  [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW]                                     [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW]                                   [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey]                                       [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA]                                    [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA]                                     [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA]                                [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA]                              [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA]                                [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA]                                  [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA]                                  [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA]                                       [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW]                                [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW]                                [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW]                                  [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW]                                  [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA]                                         [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA]                                       [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                         [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                               [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                                      [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                                   [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                                    [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                                      [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA]                                           [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA]                                  [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA]                                    [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA]                                    [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA]                                    [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA]                                      [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                        [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]                   [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]                      [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                                  [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW]                             [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                        [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                                   [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                        [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                                [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                            [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW]                                 [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW]                                 [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                                      [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW]                                [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW]                             [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW]                                 [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                         [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                               [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW]                                     [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW]                                      [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW]                                    [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                                [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose]                                          [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]                                     [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW]                                  [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW]                               [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW]                                 [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW]                                       [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]                                     [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW]                                      [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW]                                      [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA]                                        [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA]                                      [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                   [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                   [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW]                                     [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW]                                        [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey]                                        [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW]                                   [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW]                                      [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW]                                      [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]                                    [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA]                                   [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA]                                      [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                    [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                      [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                                    [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                      [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                   [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                     [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                     [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                                   [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject]                                      [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx]                                  [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu]                                    [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush]                                  [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow]                                     [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\RawIp                                                                                                                               pctfw2.sys
    AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                                fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39                                                                            
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                0x9B 0x4D 0xE1 0x7E ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)                                                        
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                    0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                    0x9B 0x4D 0xE1 0x7E ...

    ---- EOF - GMER 1.0.15 ----

  • lutts

    28 Posts

    426

    0

    Posted July 16th, 2010 17:00

    Hey K27,

    I forgot to mention some of the symptoms I often see when I am browsing the internet. It shows Windows Host services stopped working and norton 360 displays a message whenever the computer has an intrusion attack  and that the attack was resulted from SYSTEM32/SVCHOST.EXE or HARDDISKVOLUME3/INTERNETEXPLORER/EXPLORER.EXE.

    Here are the logs and its a huge list. I think its a terrible job to go thru this. I really appreciate your efforts.

    ARK LOG

     GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-07-16 14:19:10
    Windows 6.0.6002 Service Pack 2
    Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT            92BF6120                                                                                                                                                ZwAlertResumeThread
    SSDT            92BF5120                                                                                                                                                ZwAlertThread
    SSDT            933D5940                                                                                                                                                ZwAllocateVirtualMemory
    SSDT            913F8C98                                                                                                                                                ZwAlpcConnectPort
    SSDT            92F70048                                                                                                                                                ZwAssignProcessToJobObject
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateKey [0x8FB1B7A6]
    SSDT            933DEFC0                                                                                                                                                ZwCreateMutant
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcess [0x8FB18794]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcessEx [0x8FB18F1E]
    SSDT            933E37B8                                                                                                                                                ZwCreateSymbolicLinkObject
    SSDT            933D7380                                                                                                                                                ZwCreateThread
    SSDT            92FBE048                                                                                                                                                ZwDebugActiveProcess
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteKey [0x8FB1C1F0]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteValueKey [0x8FB1C42A]
    SSDT            933D5B58                                                                                                                                                ZwDuplicateObject
    SSDT            933D7B30                                                                                                                                                ZwFreeVirtualMemory
    SSDT            92F93048                                                                                                                                                ZwImpersonateAnonymousToken
    SSDT            92F74048                                                                                                                                                ZwImpersonateThread
    SSDT            89C9F728                                                                                                                                                ZwLoadDriver
    SSDT            933D79D0                                                                                                                                                ZwMapViewOfSection
    SSDT            92F94048                                                                                                                                                ZwOpenEvent
    SSDT            933D5DB8                                                                                                                                                ZwOpenProcess
    SSDT            9182A118                                                                                                                                                ZwOpenProcessToken
    SSDT            92FA9048                                                                                                                                                ZwOpenSection
    SSDT            933D5CA8                                                                                                                                                ZwOpenThread
    SSDT            933E13F0                                                                                                                                                ZwProtectVirtualMemory
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwRenameKey [0x8FB1D12A]
    SSDT            9190F120                                                                                                                                                ZwResumeThread
    SSDT            91909108                                                                                                                                                ZwSetContextThread
    SSDT            933D77B8                                                                                                                                                ZwSetInformationProcess
    SSDT            92FBD048                                                                                                                                                ZwSetSystemInformation
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwSetValueKey [0x8FB1C83C]
    SSDT            92FA8048                                                                                                                                                ZwSuspendProcess
    SSDT            901F7120                                                                                                                                                ZwSuspendThread
    SSDT            91825108                                                                                                                                                ZwTerminateProcess
    SSDT            901F5118                                                                                                                                                ZwTerminateThread
    SSDT            91904118                                                                                                                                                ZwUnmapViewOfSection
    SSDT            933D7E40                                                                                                                                                ZwWriteVirtualMemory
    SSDT            933E2FB0                                                                                                                                                ZwCreateThreadEx
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateUserProcess [0x8FB196B6]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text           ntkrnlpa.exe!KeSetEvent + 11D                                                                                                                           81CED880 8 Bytes  [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 131                                                                                                                           81CED894 4 Bytes  [40, 59, 3D, 93]
    .text           ntkrnlpa.exe!KeSetEvent + 13D                                                                                                                           81CED8A0 4 Bytes  [98, 8C, 3F, 91]
    .text           ntkrnlpa.exe!KeSetEvent + 191                                                                                                                           81CED8F4 4 Bytes  [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 1E9                                                                                                                           81CED94C 4 Bytes  [A6, B7, B1, 8F]
    .text           ...                                                                                                                                                    
    ?               C:\Windows\system32\Drivers\mchInjDrv.sys                                                                                                               The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose                                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4                                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile                                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4                                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey                                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4                                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess                                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4                                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx                                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4                                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection                                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4                                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey                                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4                                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey                                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4                                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey                                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4                                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile                                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4                                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey                                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4                                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess                                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4                                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile                                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4                                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather                                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4                                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory                                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4                                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess                                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4                                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW                                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA                                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW                                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 0028000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 0029000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0027000A
    .text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance                                                                                        76709EA6 5 Bytes  JMP 007C000A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos                                                                                           77B60B88 5 Bytes  JMP 012E000A
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4                                                  77A74318 2 Bytes  [35, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4                                              77A74418 2 Bytes  [05, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4                                          77A74498 2 Bytes  [29, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4                                          77A744C8 2 Bytes  [23, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4                                              77A747C8 2 Bytes  [0B, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4                                         77A747F8 2 Bytes  [11, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4                                     77A752E8 2 Bytes  [20, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4                                              77A75648 2 Bytes  [1A, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4                                        77A75658 2 Bytes  [1D, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4                                     77A75678 2 Bytes  [32, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4                                      77A75808 2 Bytes  [26, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory                                                                                          77A74D34 5 Bytes  JMP 0083000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 5 Bytes  JMP 0084000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher                                                                                       77A75DC8 5 Bytes  JMP 0082000A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A                                                                        7661C928 4 Bytes  CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW                                                            77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory                                                                  77A74D34 5 Bytes  JMP 0023000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 5 Bytes  JMP 0024000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher                                                               77A75DC8 5 Bytes  JMP 0022000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW                                                                        77B710B0 5 Bytes  JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW                                                                77B72EF5 5 Bytes  JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA                                                                        77B88152 5 Bytes  JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA                                                                77B8847D 5 Bytes  JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA                                                                    77B9D4D9 5 Bytes  JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW                                                                    77B9D5D3 5 Bytes  JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA                                                                          77B9D639 5 Bytes  JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW                                                                          77B9D65D 5 Bytes  JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D                                                                    76F88910 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25                                                                    76F88918 4 Bytes  [A7, 0A, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95                                                                    76F88988 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D                                                                    76F88990 8 Bytes  [A7, 0A, BE, 63, A4, 32, BD, ...]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream                                                                       766D1E12 5 Bytes  JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose                                                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4                                                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile                                                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4                                                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey                                                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4                                                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess                                                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4                                                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx                                                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4                                                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection                                                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4                                                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey                                                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4                                                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey                                                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4                                                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey                                                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4                                                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile                                                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4                                                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey                                                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4                                                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess                                                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4                                                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile                                                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4                                                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather                                                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4                                                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4                                                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess                                                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4                                                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW                                                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose                                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4                                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile                                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4                                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey                                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4                                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess                                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4                                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx                                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4                                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection                                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4                                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey                                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4                                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey                                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4                                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey                                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4                                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile                                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4                                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey                                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4                                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess                                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4                                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile                                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4                                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather                                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4                                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory                                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4                                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess                                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4                                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW                                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA                                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW                                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A                                                                       7661C928 4 Bytes  CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F040F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F0A0F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose                                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4                                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile                                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4                                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey                                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4                                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess                                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4                                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx                                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4                                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection                                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4                                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey                                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4                                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey                                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4                                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey                                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4                                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile                                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4                                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey                                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4                                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess                                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4                                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile                                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4                                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather                                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4                                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory                                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4                                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess                                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4                                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW                                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA                                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW                                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 006A000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 006B000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0069000A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose                                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4                                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile                                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4                                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey                                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4                                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess                                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4                                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx                                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4                                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection                                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4                                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey                                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4                                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey                                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4                                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey                                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4                                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile                                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4                                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey                                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4                                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess                                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4                                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile                                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4                                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather                                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4                                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory                                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4                                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess                                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4                                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW                                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA                                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW                                                                            77B487AD 6 Bytes  JMP 5F3B0F5A

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap]          00C0E660
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]          00C0E140
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle]         00C0D2A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent]       00C0EBE0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread]            00C0C260
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]          00C0BBD0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW]  00C0BF90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer]          00C0D100
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx]         00C0D7C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW]      00C0D550
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile]           00C0D740
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW]        00C0DC20
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile]         00C0D930
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType]             00C0D450
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile]         00C0D690
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize]             00C0D240
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile]               00C0D0C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP]                  00C0E680
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess]        00C0C110
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc]             00C0E3A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock]              00C0E2C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock]            00C0E280
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]             00C0C940
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]            00C0BA30
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle]             00C0D340
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]            00C0B9A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary]             00C0BC80
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress]          00C0A730
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile]                00C0CC90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion]              00C0E650
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW]                 00C0E920
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW]               00C0E8C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW]        00C0EB10
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW]           00C0EBB0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW]               00C0E9E0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]          00C0E5D0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]         00C0E580
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                                   [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                                    [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                                [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                          [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                                    [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                                 [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                                     [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                                        [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                                [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                                 [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                                  [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                          [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                             [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                                [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                          [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                         [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                            [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                          [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                                       [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                    [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW]                                         [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                        [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                          [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                  [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW]                                     [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW]                                     [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW]                                  [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW]                                     [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW]                                   [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey]                                       [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA]                                    [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA]                                     [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA]                                [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA]                              [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA]                                [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA]                                  [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA]                                  [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA]                                       [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW]                                [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW]                                [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW]                                  [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW]                                  [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA]                                         [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA]                                       [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                         [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                               [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                                      [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                                   [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                                    [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                                      [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA]                                           [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA]                                  [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA]                                    [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA]                                    [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA]                                    [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA]                                      [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                        [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]                   [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]                      [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                                  [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW]                             [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                        [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                                   [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                        [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                                [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                            [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW]                                 [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW]                                 [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                                      [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW]                                [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW]                             [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW]                                 [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                         [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                               [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW]                                     [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW]                                      [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW]                                    [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                                [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose]                                          [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]                                     [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW]                                  [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW]                               [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW]                                 [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW]                                       [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]                                     [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW]                                      [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW]                                      [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA]                                        [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA]                                      [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                   [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                   [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW]                                     [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW]                                        [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey]                                        [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW]                                   [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW]                                      [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW]                                      [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]                                    [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA]                                   [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA]                                      [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                    [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                      [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                                    [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                      [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                   [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                     [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                     [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                                   [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject]                                      [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx]                                  [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu]                                    [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush]                                  [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow]                                     [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\RawIp                                                                                                                               pctfw2.sys
    AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                                fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39                                                                            
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                0x9B 0x4D 0xE1 0x7E ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)                                                        
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                    0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                    0x9B 0x4D 0xE1 0x7E ...

    ---- EOF - GMER 1.0.15 ----

  • lutts

    28 Posts

    261

    0

    Posted July 16th, 2010 17:00

    HEY K27,

    I forgot to mention someof the symptoms I often see when I am browsing the internet. It shows Windows Host process stopped working and when the computer had an intrusion attack, noeton 360 will show that the attack was resulted from SYSTEM32/SVCHOST.EXE (something likethat) or HARDDISKVOLUME3/INTERNETEXPLORE/EXPLORER.EXE (something similar).

    I tried to post two logs on the same message window but the screen got stucked. I am pasting it separately as two posts. I guess it would be a terrible task to go thru this huge list. I really appreaciate your efforts.

    ARK LOG:

    GMER 1.0.15.15281 - http://www.gmer.net
    Rootkit scan 2010-07-16 14:19:10
    Windows 6.0.6002 Service Pack 2
    Running: qb58ektc.exe; Driver: C:\Users\APARNA\AppData\Local\Temp\pwryqpob.sys


    ---- System - GMER 1.0.15 ----

    SSDT            92BF6120                                                                                                                                                ZwAlertResumeThread
    SSDT            92BF5120                                                                                                                                                ZwAlertThread
    SSDT            933D5940                                                                                                                                                ZwAllocateVirtualMemory
    SSDT            913F8C98                                                                                                                                                ZwAlpcConnectPort
    SSDT            92F70048                                                                                                                                                ZwAssignProcessToJobObject
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateKey [0x8FB1B7A6]
    SSDT            933DEFC0                                                                                                                                                ZwCreateMutant
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcess [0x8FB18794]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateProcessEx [0x8FB18F1E]
    SSDT            933E37B8                                                                                                                                                ZwCreateSymbolicLinkObject
    SSDT            933D7380                                                                                                                                                ZwCreateThread
    SSDT            92FBE048                                                                                                                                                ZwDebugActiveProcess
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteKey [0x8FB1C1F0]
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwDeleteValueKey [0x8FB1C42A]
    SSDT            933D5B58                                                                                                                                                ZwDuplicateObject
    SSDT            933D7B30                                                                                                                                                ZwFreeVirtualMemory
    SSDT            92F93048                                                                                                                                                ZwImpersonateAnonymousToken
    SSDT            92F74048                                                                                                                                                ZwImpersonateThread
    SSDT            89C9F728                                                                                                                                                ZwLoadDriver
    SSDT            933D79D0                                                                                                                                                ZwMapViewOfSection
    SSDT            92F94048                                                                                                                                                ZwOpenEvent
    SSDT            933D5DB8                                                                                                                                                ZwOpenProcess
    SSDT            9182A118                                                                                                                                                ZwOpenProcessToken
    SSDT            92FA9048                                                                                                                                                ZwOpenSection
    SSDT            933D5CA8                                                                                                                                                ZwOpenThread
    SSDT            933E13F0                                                                                                                                                ZwProtectVirtualMemory
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwRenameKey [0x8FB1D12A]
    SSDT            9190F120                                                                                                                                                ZwResumeThread
    SSDT            91909108                                                                                                                                                ZwSetContextThread
    SSDT            933D77B8                                                                                                                                                ZwSetInformationProcess
    SSDT            92FBD048                                                                                                                                                ZwSetSystemInformation
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwSetValueKey [0x8FB1C83C]
    SSDT            92FA8048                                                                                                                                                ZwSuspendProcess
    SSDT            901F7120                                                                                                                                                ZwSuspendThread
    SSDT            91825108                                                                                                                                                ZwTerminateProcess
    SSDT            901F5118                                                                                                                                                ZwTerminateThread
    SSDT            91904118                                                                                                                                                ZwUnmapViewOfSection
    SSDT            933D7E40                                                                                                                                                ZwWriteVirtualMemory
    SSDT            933E2FB0                                                                                                                                                ZwCreateThreadEx
    SSDT            \SystemRoot\system32\drivers\iksysflt.sys (System Filter Device Driver/PCTools Research Pty Ltd.)                                                       ZwCreateUserProcess [0x8FB196B6]

    ---- Kernel code sections - GMER 1.0.15 ----

    .text           ntkrnlpa.exe!KeSetEvent + 11D                                                                                                                           81CED880 8 Bytes  [20, 61, BF, 92, 20, 51, BF, ...] {AND [ECX-0x41], AH; XCHG EDX, EAX; AND [ECX-0x41], DL; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 131                                                                                                                           81CED894 4 Bytes  [40, 59, 3D, 93]
    .text           ntkrnlpa.exe!KeSetEvent + 13D                                                                                                                           81CED8A0 4 Bytes  [98, 8C, 3F, 91]
    .text           ntkrnlpa.exe!KeSetEvent + 191                                                                                                                           81CED8F4 4 Bytes  [48, 00, F7, 92] {DEC EAX; ADD BH, DH; XCHG EDX, EAX}
    .text           ntkrnlpa.exe!KeSetEvent + 1E9                                                                                                                           81CED94C 4 Bytes  [A6, B7, B1, 8F]
    .text           ...                                                                                                                                                    
    ?               C:\Windows\system32\Drivers\mchInjDrv.sys                                                                                                               The system cannot find the file specified. !

    ---- User code sections - GMER 1.0.15 ----

    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Dwm.exe[172] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Dwm.exe[172] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Dwm.exe[172] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[600] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[600] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[600] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wininit.exe[652] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wininit.exe[652] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wininit.exe[652] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\csrss.exe[660] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\csrss.exe[660] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\csrss.exe[660] KERNEL32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\services.exe[700] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\services.exe[700] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\services.exe[700] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose                                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtClose + 4                                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile                                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateFile + 4                                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey                                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateKey + 4                                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess                                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcess + 4                                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx                                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateProcessEx + 4                                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection                                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateSection + 4                                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey                                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteKey + 4                                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey                                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtDeleteValueKey + 4                                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey                                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtRenameKey + 4                                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile                                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetInformationFile + 4                                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey                                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtSetValueKey + 4                                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess                                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtTerminateProcess + 4                                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile                                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFile + 4                                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather                                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteFileGather + 4                                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory                                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtWriteVirtualMemory + 4                                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess                                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsass.exe[712] ntdll.dll!NtCreateUserProcess + 4                                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsass.exe[712] kernel32.dll!LoadLibraryExW                                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExA                                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsass.exe[712] USER32.dll!SetWindowsHookExW                                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose                                                                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtClose + 4                                                                                                  77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile                                                                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateFile + 4                                                                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey                                                                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateKey + 4                                                                                              77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess                                                                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcess + 4                                                                                          77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx                                                                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateProcessEx + 4                                                                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection                                                                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateSection + 4                                                                                          77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey                                                                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteKey + 4                                                                                              77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey                                                                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtDeleteValueKey + 4                                                                                         77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey                                                                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtRenameKey + 4                                                                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile                                                                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetInformationFile + 4                                                                                     77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey                                                                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtSetValueKey + 4                                                                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess                                                                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtTerminateProcess + 4                                                                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile                                                                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFile + 4                                                                                              77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather                                                                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteFileGather + 4                                                                                        77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory                                                                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtWriteVirtualMemory + 4                                                                                     77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess                                                                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\lsm.exe[720] ntdll.dll!NtCreateUserProcess + 4                                                                                      77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\lsm.exe[720] kernel32.dll!LoadLibraryExW                                                                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExA                                                                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\lsm.exe[720] USER32.dll!SetWindowsHookExW                                                                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[880] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[880] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[880] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose                                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtClose + 4                                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile                                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateFile + 4                                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey                                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateKey + 4                                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess                                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcess + 4                                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx                                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateProcessEx + 4                                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection                                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateSection + 4                                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey                                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteKey + 4                                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey                                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtDeleteValueKey + 4                                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey                                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtRenameKey + 4                                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile                                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetInformationFile + 4                                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey                                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtSetValueKey + 4                                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess                                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtTerminateProcess + 4                                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile                                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFile + 4                                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather                                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteFileGather + 4                                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory                                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtWriteVirtualMemory + 4                                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess                                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[932] ntdll.dll!NtCreateUserProcess + 4                                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[932] kernel32.dll!LoadLibraryExW                                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExA                                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[932] USER32.dll!SetWindowsHookExW                                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[964] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[964] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[964] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1004] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1004] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1004] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1064] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1064] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1064] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\winlogon.exe[1092] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\winlogon.exe[1092] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\winlogon.exe[1092] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[1124] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[1124] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[1124] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 0028000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 0029000A
    .text           C:\Windows\system32\svchost.exe[1148] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0027000A
    .text           C:\Windows\system32\svchost.exe[1148] ole32.dll!CoCreateInstance                                                                                        76709EA6 5 Bytes  JMP 007C000A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\svchost.exe[1148] USER32.dll!GetCursorPos                                                                                           77B60B88 5 Bytes  JMP 012E000A
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\aestsrv.exe[1308] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\aestsrv.exe[1308] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\aestsrv.exe[1308] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1460] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1460] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1460] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\nvvsvc.exe[1512] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\nvvsvc.exe[1512] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\nvvsvc.exe[1512] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe[1520] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DockLogin.exe[1604] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\EvtEng.exe[1636] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose                                                      77A74314 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtClose + 4                                                  77A74318 2 Bytes  [35, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile                                                 77A743D4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateFile + 4                                             77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey                                                  77A74414 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateKey + 4                                              77A74418 2 Bytes  [05, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess                                              77A74494 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcess + 4                                          77A74498 2 Bytes  [29, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx                                            77A744A4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateProcessEx + 4                                        77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection                                              77A744C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateSection + 4                                          77A744C8 2 Bytes  [23, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey                                                  77A747C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteKey + 4                                              77A747C8 2 Bytes  [0B, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey                                             77A747F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtDeleteValueKey + 4                                         77A747F8 2 Bytes  [11, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey                                                  77A750C4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtRenameKey + 4                                              77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile                                         77A752E4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetInformationFile + 4                                     77A752E8 2 Bytes  [20, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey                                                77A75454 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtSetValueKey + 4                                            77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess                                           77A754F4 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtTerminateProcess + 4                                       77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile                                                  77A75644 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFile + 4                                              77A75648 2 Bytes  [1A, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather                                            77A75654 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteFileGather + 4                                        77A75658 2 Bytes  [1D, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory                                         77A75674 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtWriteVirtualMemory + 4                                     77A75678 2 Bytes  [32, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess                                          77A75804 3 Bytes  [FF, 25, 1E]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] ntdll.dll!NtCreateUserProcess + 4                                      77A75808 2 Bytes  [26, 5F]
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] kernel32.dll!LoadLibraryExW                                            765F9109 5 Bytes  JMP 5F070F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExA                                           77B46322 6 Bytes  JMP 5F370F5A
    .text           c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] USER32.dll!SetWindowsHookExW                                           77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1680] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1680] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1680] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtClose + 4                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateFile + 4                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateKey + 4                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcess + 4                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateProcessEx + 4                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateSection + 4                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteKey + 4                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtDeleteValueKey + 4                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtRenameKey + 4                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetInformationFile + 4                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtSetValueKey + 4                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtTerminateProcess + 4                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFile + 4                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteFileGather + 4                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtWriteVirtualMemory + 4                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] ntdll.dll!NtCreateUserProcess + 4                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] kernel32.dll!LoadLibraryExW                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExA                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\upeksvr.exe[1808] USER32.dll!SetWindowsHookExW                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\WLANExt.exe[1824] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\WLANExt.exe[1824] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\WLANExt.exe[1824] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\spoolsv.exe[1920] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\spoolsv.exe[1920] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\spoolsv.exe[1920] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[1984] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[1984] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[1984] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtClose + 4                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateFile + 4                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateKey + 4                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcess + 4                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateProcessEx + 4                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateSection + 4                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteKey + 4                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtDeleteValueKey + 4                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtRenameKey + 4                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetInformationFile + 4                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtSetValueKey + 4                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtTerminateProcess + 4                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFile + 4                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteFileGather + 4                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtWriteVirtualMemory + 4                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] ntdll.dll!NtCreateUserProcess + 4                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] kernel32.dll!LoadLibraryExW                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExA                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Norton 360\Norton 360\Engine\4.2.0.12\ccSvcHst.exe[2156] USER32.dll!SetWindowsHookExW                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[2424] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[2500] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[2500] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[2500] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2612] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2612] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2612] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe[2632] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtsvc.exe[2712] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtProtectVirtualMemory                                                                                          77A74D34 5 Bytes  JMP 0083000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 5 Bytes  JMP 0084000A
    .text           C:\Windows\Explorer.EXE[2740] ntdll.dll!KiUserExceptionDispatcher                                                                                       77A75DC8 5 Bytes  JMP 0082000A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\Explorer.EXE[2740] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\DllHost.exe[2756] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\DllHost.exe[2756] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\DllHost.exe[2756] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[2792] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[2792] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[2792] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtClose + 4                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateFile + 4                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateKey + 4                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcess + 4                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateProcessEx + 4                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateSection + 4                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteKey + 4                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtDeleteValueKey + 4                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtRenameKey + 4                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetInformationFile + 4                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtSetValueKey + 4                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtTerminateProcess + 4                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFile + 4                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteFileGather + 4                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtWriteVirtualMemory + 4                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] ntdll.dll!NtCreateUserProcess + 4                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] kernel32.dll!LoadLibraryExW                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe[2832] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spyware Doctor\pctsAuxs.exe[2876] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] kernel32.dll!CreateThread + 1A                                                                        7661C928 4 Bytes  CALL 0044A801 C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnetwk.exe[3024] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtClose + 4                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateFile + 4                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateKey + 4                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcess + 4                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateProcessEx + 4                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateSection + 4                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteKey + 4                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtDeleteValueKey + 4                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtRenameKey + 4                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetInformationFile + 4                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtSetValueKey + 4                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtTerminateProcess + 4                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFile + 4                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteFileGather + 4                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtWriteVirtualMemory + 4                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] ntdll.dll!NtCreateUserProcess + 4                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] kernel32.dll!LoadLibraryExW                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExA                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe[3180] USER32.dll!SetWindowsHookExW                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\STacSV.exe[3244] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\STacSV.exe[3244] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\STacSV.exe[3244] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\svchost.exe[3312] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\svchost.exe[3312] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\svchost.exe[3312] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[3352] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[3352] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[3352] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe[3388] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtClose + 4                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateFile + 4                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateKey + 4                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcess + 4                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateProcessEx + 4                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateSection + 4                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteKey + 4                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtDeleteValueKey + 4                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtRenameKey + 4                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetInformationFile + 4                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtSetValueKey + 4                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtTerminateProcess + 4                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFile + 4                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteFileGather + 4                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtWriteVirtualMemory + 4                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] ntdll.dll!NtCreateUserProcess + 4                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] kernel32.dll!LoadLibraryExW                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExA                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE[3500] USER32.dll!SetWindowsHookExW                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\taskeng.exe[3568] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\taskeng.exe[3568] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\taskeng.exe[3568] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\SearchIndexer.exe[3652] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\SearchIndexer.exe[3652] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\HidFind.exe[3700] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtClose + 4                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateFile + 4                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateKey + 4                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcess + 4                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateProcessEx + 4                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateSection + 4                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteKey + 4                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtDeleteValueKey + 4                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtRenameKey + 4                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetInformationFile + 4                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtSetValueKey + 4                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtTerminateProcess + 4                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFile + 4                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteFileGather + 4                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtWriteVirtualMemory + 4                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] ntdll.dll!NtCreateUserProcess + 4                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] kernel32.dll!LoadLibraryExW                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExA                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe[3772] USER32.dll!SetWindowsHookExW                                                            77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe[3940] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtProtectVirtualMemory                                                                  77A74D34 5 Bytes  JMP 0023000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!NtWriteVirtualMemory                                                                    77A75674 5 Bytes  JMP 0024000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ntdll.dll!KiUserExceptionDispatcher                                                               77A75DC8 5 Bytes  JMP 0022000A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExA                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!SetWindowsHookExW                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamW                                                                        77B710B0 5 Bytes  JMP 6BE7BF9F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamW                                                                77B72EF5 5 Bytes  JMP 6BFBB45A C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxParamA                                                                        77B88152 5 Bytes  JMP 6BFBB41F C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!DialogBoxIndirectParamA                                                                77B8847D 5 Bytes  JMP 6BFBB495 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectA                                                                    77B9D4D9 5 Bytes  JMP 6BFBB3DB C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxIndirectW                                                                    77B9D5D3 5 Bytes  JMP 6BFBB397 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExA                                                                          77B9D639 5 Bytes  JMP 6BFBB35D C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] USER32.dll!MessageBoxExW                                                                          77B9D65D 5 Bytes  JMP 6BFBB323 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D1D                                                                    76F88910 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D25                                                                    76F88918 4 Bytes  [A7, 0A, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D95                                                                    76F88988 4 Bytes  [99, 0B, BE, 63]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] SHELL32.dll!SHRestricted + D9D                                                                    76F88990 8 Bytes  [A7, 0A, BE, 63, A4, 32, BD, ...]
    .text           C:\Program Files\Internet Explorer\iexplore.exe[4392] ole32.dll!OleLoadFromStream                                                                       766D1E12 5 Bytes  JMP 6BFBB657 C:\Windows\system32\IEFRAME.dll (Internet Explorer/Microsoft Corporation)
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apoint.exe[4496] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose                                                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtClose + 4                                                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile                                                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateFile + 4                                                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey                                                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateKey + 4                                                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess                                                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcess + 4                                                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx                                                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateProcessEx + 4                                                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection                                                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateSection + 4                                                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey                                                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteKey + 4                                                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey                                                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtDeleteValueKey + 4                                                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey                                                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtRenameKey + 4                                                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile                                                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetInformationFile + 4                                                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey                                                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtSetValueKey + 4                                                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess                                                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtTerminateProcess + 4                                                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile                                                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFile + 4                                                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather                                                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteFileGather + 4                                                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory                                                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtWriteVirtualMemory + 4                                                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess                                                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\OEM02Mon.exe[4564] ntdll.dll!NtCreateUserProcess + 4                                                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\OEM02Mon.exe[4564] kernel32.dll!LoadLibraryExW                                                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExA                                                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\OEM02Mon.exe[4564] USER32.dll!SetWindowsHookExW                                                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] KERNEL32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\DellDock\DellDock.exe[4612] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Internet Explorer\ieuser.exe[4648] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtClose + 4                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateFile + 4                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateKey + 4                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcess + 4                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateProcessEx + 4                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateSection + 4                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteKey + 4                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtDeleteValueKey + 4                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtRenameKey + 4                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetInformationFile + 4                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtSetValueKey + 4                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtTerminateProcess + 4                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFile + 4                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteFileGather + 4                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtWriteVirtualMemory + 4                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] ntdll.dll!NtCreateUserProcess + 4                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] kernel32.dll!LoadLibraryExW                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExA                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe[4676] USER32.dll!SetWindowsHookExW                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose                                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtClose + 4                                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile                                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateFile + 4                                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey                                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateKey + 4                                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess                                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcess + 4                                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx                                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateProcessEx + 4                                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection                                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateSection + 4                                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey                                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteKey + 4                                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey                                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtDeleteValueKey + 4                                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey                                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtRenameKey + 4                                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile                                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetInformationFile + 4                                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey                                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtSetValueKey + 4                                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess                                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtTerminateProcess + 4                                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile                                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFile + 4                                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather                                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteFileGather + 4                                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory                                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtWriteVirtualMemory + 4                                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess                                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] ntdll.dll!NtCreateUserProcess + 4                                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] kernel32.dll!LoadLibraryExW                                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExA                                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Toolbar\wltuser.exe[4700] USER32.dll!SetWindowsHookExW                                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtClose + 4                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateFile + 4                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateKey + 4                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcess + 4                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateProcessEx + 4                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateSection + 4                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteKey + 4                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtDeleteValueKey + 4                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtRenameKey + 4                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetInformationFile + 4                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtSetValueKey + 4                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtTerminateProcess + 4                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFile + 4                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteFileGather + 4                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtWriteVirtualMemory + 4                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] ntdll.dll!NtCreateUserProcess + 4                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] kernel32.dll!LoadLibraryExW                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExA                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe[4720] USER32.dll!SetWindowsHookExW                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtClose + 4                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateFile + 4                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateKey + 4                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcess + 4                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateProcessEx + 4                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateSection + 4                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteKey + 4                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtDeleteValueKey + 4                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtRenameKey + 4                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetInformationFile + 4                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtSetValueKey + 4                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtTerminateProcess + 4                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFile + 4                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteFileGather + 4                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtWriteVirtualMemory + 4                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] ntdll.dll!NtCreateUserProcess + 4                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] kernel32.dll!LoadLibraryExW                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExA                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\MediaDirect\PCMService.exe[4744] USER32.dll!SetWindowsHookExW                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] KERNEL32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell DataSafe Online\DataSafeOnline.exe[4776] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\rundll32.exe[4816] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\rundll32.exe[4816] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\rundll32.exe[4816] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Support Center\bin\sprtcmd.exe[4844] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtClose + 4                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateFile + 4                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateKey + 4                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcess + 4                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateProcessEx + 4                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateSection + 4                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteKey + 4                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtDeleteValueKey + 4                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtRenameKey + 4                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetInformationFile + 4                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtSetValueKey + 4                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtTerminateProcess + 4                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFile + 4                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteFileGather + 4                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtWriteVirtualMemory + 4                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] ntdll.dll!NtCreateUserProcess + 4                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] kernel32.dll!LoadLibraryExW                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExA                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe[4864] USER32.dll!SetWindowsHookExW                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe[4892] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\HP Software Update\hpwuSchd2.exe[4912] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose                                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtClose + 4                                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile                                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateFile + 4                                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey                                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateKey + 4                                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess                                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcess + 4                                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx                                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateProcessEx + 4                                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection                                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateSection + 4                                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey                                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteKey + 4                                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey                                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtDeleteValueKey + 4                                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey                                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtRenameKey + 4                                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile                                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetInformationFile + 4                                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey                                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtSetValueKey + 4                                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess                                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtTerminateProcess + 4                                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile                                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFile + 4                                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather                                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteFileGather + 4                                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory                                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtWriteVirtualMemory + 4                                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess                                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] ntdll.dll!NtCreateUserProcess + 4                                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] kernel32.dll!LoadLibraryExW                                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExA                                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe[4980] USER32.dll!SetWindowsHookExW                                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose                                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtClose + 4                                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile                                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateFile + 4                                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey                                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateKey + 4                                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess                                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcess + 4                                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx                                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateProcessEx + 4                                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection                                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateSection + 4                                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey                                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteKey + 4                                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey                                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtDeleteValueKey + 4                                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey                                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtRenameKey + 4                                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile                                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetInformationFile + 4                                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey                                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtSetValueKey + 4                                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess                                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtTerminateProcess + 4                                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile                                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFile + 4                                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather                                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteFileGather + 4                                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory                                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtWriteVirtualMemory + 4                                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess                                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\wpcumi.exe[4988] ntdll.dll!NtCreateUserProcess + 4                                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\wpcumi.exe[4988] kernel32.dll!LoadLibraryExW                                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExA                                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\wpcumi.exe[4988] USER32.dll!SetWindowsHookExW                                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] kernel32.dll!CreateThread + 1A                                                                       7661C928 4 Bytes  CALL 0044A815 C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F040F5A
    .text           C:\Program Files\Spyware Doctor\pctsTray.exe[5020] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F0A0F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose                                                               77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtClose + 4                                                           77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile                                                          77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateFile + 4                                                      77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey                                                           77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateKey + 4                                                       77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess                                                       77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcess + 4                                                   77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx                                                     77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateProcessEx + 4                                                 77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection                                                       77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateSection + 4                                                   77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey                                                           77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteKey + 4                                                       77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey                                                      77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtDeleteValueKey + 4                                                  77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey                                                           77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtRenameKey + 4                                                       77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile                                                  77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetInformationFile + 4                                              77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey                                                         77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtSetValueKey + 4                                                     77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess                                                    77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtTerminateProcess + 4                                                77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile                                                           77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFile + 4                                                       77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather                                                     77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteFileGather + 4                                                 77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory                                                  77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtWriteVirtualMemory + 4                                              77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess                                                   77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] ntdll.dll!NtCreateUserProcess + 4                                               77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] kernel32.dll!LoadLibraryExW                                                     765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExA                                                    77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\AppData\Roaming\Google\Google Talk\googletalk.exe[5040] USER32.dll!SetWindowsHookExW                                                    77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose                                                                             77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtClose + 4                                                                         77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile                                                                        77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateFile + 4                                                                    77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey                                                                         77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateKey + 4                                                                     77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess                                                                     77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcess + 4                                                                 77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx                                                                   77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateProcessEx + 4                                                               77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection                                                                     77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateSection + 4                                                                 77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey                                                                         77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteKey + 4                                                                     77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey                                                                    77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtDeleteValueKey + 4                                                                77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey                                                                         77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtRenameKey + 4                                                                     77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile                                                                77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetInformationFile + 4                                                            77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey                                                                       77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtSetValueKey + 4                                                                   77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess                                                                  77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtTerminateProcess + 4                                                              77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile                                                                         77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFile + 4                                                                     77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather                                                                   77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteFileGather + 4                                                               77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory                                                                77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtWriteVirtualMemory + 4                                                            77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess                                                                 77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] ntdll.dll!NtCreateUserProcess + 4                                                             77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] kernel32.dll!LoadLibraryExW                                                                   765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExA                                                                  77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Live\Messenger\msnmsgr.exe[5072] USER32.dll!SetWindowsHookExW                                                                  77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtProtectVirtualMemory                                                                                  77A74D34 5 Bytes  JMP 006A000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 5 Bytes  JMP 006B000A
    .text           C:\Windows\system32\wuauclt.exe[5080] ntdll.dll!KiUserExceptionDispatcher                                                                               77A75DC8 5 Bytes  JMP 0069000A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F340F5A
    .text           C:\Windows\system32\wuauclt.exe[5080] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F380F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose                                                                                   77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtClose + 4                                                                               77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile                                                                              77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateFile + 4                                                                          77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey                                                                               77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateKey + 4                                                                           77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess                                                                           77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcess + 4                                                                       77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx                                                                         77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateProcessEx + 4                                                                     77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection                                                                           77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateSection + 4                                                                       77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey                                                                               77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteKey + 4                                                                           77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey                                                                          77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtDeleteValueKey + 4                                                                      77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey                                                                               77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtRenameKey + 4                                                                           77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile                                                                      77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetInformationFile + 4                                                                  77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey                                                                             77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtSetValueKey + 4                                                                         77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess                                                                        77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtTerminateProcess + 4                                                                    77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile                                                                               77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFile + 4                                                                           77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather                                                                         77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteFileGather + 4                                                                     77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory                                                                      77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtWriteVirtualMemory + 4                                                                  77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess                                                                       77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] ntdll.dll!NtCreateUserProcess + 4                                                                   77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] kernel32.dll!LoadLibraryExW                                                                         765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExA                                                                        77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Jumblo.com\Jumblo\Jumblo.exe[5096] USER32.dll!SetWindowsHookExW                                                                        77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose                                                        77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtClose + 4                                                    77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile                                                   77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateFile + 4                                               77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey                                                    77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateKey + 4                                                77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess                                                77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcess + 4                                            77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx                                              77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateProcessEx + 4                                          77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection                                                77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateSection + 4                                            77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey                                                    77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteKey + 4                                                77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey                                               77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtDeleteValueKey + 4                                           77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey                                                    77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtRenameKey + 4                                                77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile                                           77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetInformationFile + 4                                       77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey                                                  77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtSetValueKey + 4                                              77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess                                             77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtTerminateProcess + 4                                         77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile                                                    77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFile + 4                                                77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather                                              77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteFileGather + 4                                          77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory                                           77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtWriteVirtualMemory + 4                                       77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess                                            77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] ntdll.dll!NtCreateUserProcess + 4                                        77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] kernel32.dll!LoadLibraryExW                                              765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExA                                             77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe[5104] USER32.dll!SetWindowsHookExW                                             77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose                                                                              77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtClose + 4                                                                          77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile                                                                         77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateFile + 4                                                                     77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey                                                                          77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateKey + 4                                                                      77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess                                                                      77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcess + 4                                                                  77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx                                                                    77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateProcessEx + 4                                                                77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection                                                                      77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateSection + 4                                                                  77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey                                                                          77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteKey + 4                                                                      77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey                                                                     77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtDeleteValueKey + 4                                                                 77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey                                                                          77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtRenameKey + 4                                                                      77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile                                                                 77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetInformationFile + 4                                                             77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey                                                                        77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtSetValueKey + 4                                                                    77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess                                                                   77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtTerminateProcess + 4                                                               77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile                                                                          77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFile + 4                                                                      77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather                                                                    77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteFileGather + 4                                                                77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory                                                                 77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtWriteVirtualMemory + 4                                                             77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess                                                                  77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] ntdll.dll!NtCreateUserProcess + 4                                                              77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] kernel32.dll!LoadLibraryExW                                                                    765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExA                                                                   77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Windows Media Player\wmpnscfg.exe[5112] USER32.dll!SetWindowsHookExW                                                                   77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose                                                                         77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtClose + 4                                                                     77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile                                                                    77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateFile + 4                                                                77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey                                                                     77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateKey + 4                                                                 77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess                                                                 77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcess + 4                                                             77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx                                                               77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateProcessEx + 4                                                           77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection                                                                 77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateSection + 4                                                             77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey                                                                     77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteKey + 4                                                                 77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey                                                                77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtDeleteValueKey + 4                                                            77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey                                                                     77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtRenameKey + 4                                                                 77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile                                                            77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetInformationFile + 4                                                        77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey                                                                   77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtSetValueKey + 4                                                               77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess                                                              77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtTerminateProcess + 4                                                          77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile                                                                     77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFile + 4                                                                 77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather                                                               77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteFileGather + 4                                                           77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory                                                            77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtWriteVirtualMemory + 4                                                        77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess                                                             77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] ntdll.dll!NtCreateUserProcess + 4                                                         77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] kernel32.dll!LoadLibraryExW                                                               765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExA                                                              77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe[5128] USER32.dll!SetWindowsHookExW                                                              77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose                                                                                    77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtClose + 4                                                                                77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile                                                                               77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateFile + 4                                                                           77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey                                                                                77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateKey + 4                                                                            77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess                                                                            77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcess + 4                                                                        77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx                                                                          77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateProcessEx + 4                                                                      77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection                                                                            77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateSection + 4                                                                        77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey                                                                                77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteKey + 4                                                                            77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey                                                                           77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtDeleteValueKey + 4                                                                       77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey                                                                                77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtRenameKey + 4                                                                            77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile                                                                       77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetInformationFile + 4                                                                   77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey                                                                              77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtSetValueKey + 4                                                                          77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess                                                                         77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtTerminateProcess + 4                                                                     77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile                                                                                77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFile + 4                                                                            77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather                                                                          77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteFileGather + 4                                                                      77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory                                                                       77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtWriteVirtualMemory + 4                                                                   77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess                                                                        77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] ntdll.dll!NtCreateUserProcess + 4                                                                    77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] kernel32.dll!LoadLibraryExW                                                                          765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExA                                                                         77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\1-Click Answers\answers.exe[5196] USER32.dll!SetWindowsHookExW                                                                         77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe[5248] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose                                                                                  77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtClose + 4                                                                              77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile                                                                             77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateFile + 4                                                                         77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey                                                                              77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateKey + 4                                                                          77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess                                                                          77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcess + 4                                                                      77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx                                                                        77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateProcessEx + 4                                                                    77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection                                                                          77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateSection + 4                                                                      77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey                                                                              77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteKey + 4                                                                          77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey                                                                         77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtDeleteValueKey + 4                                                                     77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey                                                                              77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtRenameKey + 4                                                                          77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile                                                                     77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetInformationFile + 4                                                                 77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey                                                                            77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtSetValueKey + 4                                                                        77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess                                                                       77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtTerminateProcess + 4                                                                   77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile                                                                              77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFile + 4                                                                          77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather                                                                        77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteFileGather + 4                                                                    77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory                                                                     77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtWriteVirtualMemory + 4                                                                 77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess                                                                      77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] ntdll.dll!NtCreateUserProcess + 4                                                                  77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] kernel32.dll!LoadLibraryExW                                                                        765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExA                                                                       77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell Remote Access\ezi_ra.exe[5276] USER32.dll!SetWindowsHookExW                                                                       77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtClose + 4                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateFile + 4                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateKey + 4                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcess + 4                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateProcessEx + 4                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateSection + 4                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteKey + 4                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtDeleteValueKey + 4                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtRenameKey + 4                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetInformationFile + 4                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtSetValueKey + 4                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtTerminateProcess + 4                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFile + 4                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteFileGather + 4                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtWriteVirtualMemory + 4                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] ntdll.dll!NtCreateUserProcess + 4                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] kernel32.dll!LoadLibraryExW                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExA                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe[5296] USER32.dll!SetWindowsHookExW                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose                                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtClose + 4                                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile                                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateFile + 4                                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey                                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateKey + 4                                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess                                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcess + 4                                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx                                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateProcessEx + 4                                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection                                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateSection + 4                                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey                                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteKey + 4                                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey                                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtDeleteValueKey + 4                                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey                                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtRenameKey + 4                                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile                                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetInformationFile + 4                                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey                                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtSetValueKey + 4                                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess                                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtTerminateProcess + 4                                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile                                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFile + 4                                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather                                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteFileGather + 4                                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory                                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtWriteVirtualMemory + 4                                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess                                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] ntdll.dll!NtCreateUserProcess + 4                                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] kernel32.dll!LoadLibraryExW                                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExA                                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Dell\QuickSet\quickset.exe[5316] USER32.dll!SetWindowsHookExW                                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\ApMsgFwd.exe[5356] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose                                                                                                 77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtClose + 4                                                                                             77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile                                                                                            77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateFile + 4                                                                                        77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey                                                                                             77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateKey + 4                                                                                         77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess                                                                                         77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcess + 4                                                                                     77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx                                                                                       77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateProcessEx + 4                                                                                   77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection                                                                                         77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateSection + 4                                                                                     77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey                                                                                             77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteKey + 4                                                                                         77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey                                                                                        77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtDeleteValueKey + 4                                                                                    77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey                                                                                             77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtRenameKey + 4                                                                                         77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile                                                                                    77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetInformationFile + 4                                                                                77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey                                                                                           77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtSetValueKey + 4                                                                                       77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess                                                                                      77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtTerminateProcess + 4                                                                                  77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile                                                                                             77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFile + 4                                                                                         77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather                                                                                       77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteFileGather + 4                                                                                   77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory                                                                                    77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtWriteVirtualMemory + 4                                                                                77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess                                                                                     77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\System32\svchost.exe[5456] ntdll.dll!NtCreateUserProcess + 4                                                                                 77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\System32\svchost.exe[5456] kernel32.dll!LoadLibraryExW                                                                                       765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExA                                                                                      77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\System32\svchost.exe[5456] USER32.dll!SetWindowsHookExW                                                                                      77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose                                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtClose + 4                                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile                                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateFile + 4                                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey                                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateKey + 4                                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess                                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcess + 4                                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx                                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateProcessEx + 4                                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection                                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateSection + 4                                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey                                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteKey + 4                                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey                                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtDeleteValueKey + 4                                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey                                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtRenameKey + 4                                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile                                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetInformationFile + 4                                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey                                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtSetValueKey + 4                                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess                                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtTerminateProcess + 4                                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile                                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFile + 4                                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather                                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteFileGather + 4                                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory                                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtWriteVirtualMemory + 4                                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess                                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] ntdll.dll!NtCreateUserProcess + 4                                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] kernel32.dll!LoadLibraryExW                                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExA                                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Users\APARNA\Downloads\qb58ektc.exe[5512] USER32.dll!SetWindowsHookExW                                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose                                                                          77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtClose + 4                                                                      77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile                                                                     77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateFile + 4                                                                 77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey                                                                      77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateKey + 4                                                                  77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess                                                                  77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcess + 4                                                              77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx                                                                77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateProcessEx + 4                                                            77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection                                                                  77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateSection + 4                                                              77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey                                                                      77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteKey + 4                                                                  77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey                                                                 77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtDeleteValueKey + 4                                                             77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey                                                                      77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtRenameKey + 4                                                                  77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile                                                             77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetInformationFile + 4                                                         77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey                                                                    77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtSetValueKey + 4                                                                77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess                                                               77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtTerminateProcess + 4                                                           77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile                                                                      77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFile + 4                                                                  77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather                                                                77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteFileGather + 4                                                            77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory                                                             77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtWriteVirtualMemory + 4                                                         77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess                                                              77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] ntdll.dll!NtCreateUserProcess + 4                                                          77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] kernel32.dll!LoadLibraryExW                                                                765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExA                                                               77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\Fingerprint Reader Suite\psqltray.exe[5732] USER32.dll!SetWindowsHookExW                                                               77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose                                                                                           77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtClose + 4                                                                                       77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile                                                                                      77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateFile + 4                                                                                  77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey                                                                                       77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateKey + 4                                                                                   77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess                                                                                   77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcess + 4                                                                               77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx                                                                                 77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateProcessEx + 4                                                                             77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection                                                                                   77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateSection + 4                                                                               77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey                                                                                       77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteKey + 4                                                                                   77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey                                                                                  77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtDeleteValueKey + 4                                                                              77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey                                                                                       77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtRenameKey + 4                                                                                   77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile                                                                              77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetInformationFile + 4                                                                          77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey                                                                                     77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtSetValueKey + 4                                                                                 77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess                                                                                77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtTerminateProcess + 4                                                                            77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile                                                                                       77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFile + 4                                                                                   77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather                                                                                 77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteFileGather + 4                                                                             77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory                                                                              77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtWriteVirtualMemory + 4                                                                          77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess                                                                               77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] ntdll.dll!NtCreateUserProcess + 4                                                                           77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] kernel32.dll!LoadLibraryExW                                                                                 765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExA                                                                                77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\wbem\wmiprvse.exe[5744] USER32.dll!SetWindowsHookExW                                                                                77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose                                                                                                77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtClose + 4                                                                                            77A74318 2 Bytes  [35, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile                                                                                           77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateFile + 4                                                                                       77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey                                                                                            77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateKey + 4                                                                                        77A74418 2 Bytes  [05, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess                                                                                        77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcess + 4                                                                                    77A74498 2 Bytes  [29, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx                                                                                      77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateProcessEx + 4                                                                                  77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection                                                                                        77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateSection + 4                                                                                    77A744C8 2 Bytes  [23, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey                                                                                            77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteKey + 4                                                                                        77A747C8 2 Bytes  [0B, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey                                                                                       77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtDeleteValueKey + 4                                                                                   77A747F8 2 Bytes  [11, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey                                                                                            77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtRenameKey + 4                                                                                        77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile                                                                                   77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetInformationFile + 4                                                                               77A752E8 2 Bytes  [20, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey                                                                                          77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtSetValueKey + 4                                                                                      77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess                                                                                     77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtTerminateProcess + 4                                                                                 77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile                                                                                            77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFile + 4                                                                                        77A75648 2 Bytes  [1A, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather                                                                                      77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteFileGather + 4                                                                                  77A75658 2 Bytes  [1D, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory                                                                                   77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtWriteVirtualMemory + 4                                                                               77A75678 2 Bytes  [32, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess                                                                                    77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] ntdll.dll!NtCreateUserProcess + 4                                                                                77A75808 2 Bytes  [26, 5F]
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] kernel32.dll!LoadLibraryExW                                                                                      765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExA                                                                                     77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\PROGRA~1\1-CLIC~1\agtserv.exe[5932] USER32.dll!SetWindowsHookExW                                                                                     77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose                                                                                            77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtClose + 4                                                                                        77A74318 2 Bytes  [35, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile                                                                                       77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateFile + 4                                                                                   77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey                                                                                        77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateKey + 4                                                                                    77A74418 2 Bytes  [05, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess                                                                                    77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcess + 4                                                                                77A74498 2 Bytes  [29, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx                                                                                  77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateProcessEx + 4                                                                              77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection                                                                                    77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateSection + 4                                                                                77A744C8 2 Bytes  [23, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey                                                                                        77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteKey + 4                                                                                    77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey                                                                                   77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtDeleteValueKey + 4                                                                               77A747F8 2 Bytes  [11, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey                                                                                        77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtRenameKey + 4                                                                                    77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile                                                                               77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetInformationFile + 4                                                                           77A752E8 2 Bytes  [20, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey                                                                                      77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtSetValueKey + 4                                                                                  77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess                                                                                 77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtTerminateProcess + 4                                                                             77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile                                                                                        77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFile + 4                                                                                    77A75648 2 Bytes  [1A, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather                                                                                  77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteFileGather + 4                                                                              77A75658 2 Bytes  [1D, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory                                                                               77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtWriteVirtualMemory + 4                                                                           77A75678 2 Bytes  [32, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess                                                                                77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] ntdll.dll!NtCreateUserProcess + 4                                                                            77A75808 2 Bytes  [26, 5F]
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] kernel32.dll!LoadLibraryExW                                                                                  765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExA                                                                                 77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Program Files\DellTPad\Apntex.exe[6120] USER32.dll!SetWindowsHookExW                                                                                 77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose                                                                     77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtClose + 4                                                                 77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile                                                                77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateFile + 4                                                            77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey                                                                 77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateKey + 4                                                             77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess                                                             77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcess + 4                                                         77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx                                                           77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateProcessEx + 4                                                       77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection                                                             77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateSection + 4                                                         77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey                                                                 77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteKey + 4                                                             77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey                                                            77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtDeleteValueKey + 4                                                        77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey                                                                 77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtRenameKey + 4                                                             77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile                                                        77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetInformationFile + 4                                                    77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey                                                               77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtSetValueKey + 4                                                           77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess                                                          77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtTerminateProcess + 4                                                      77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile                                                                 77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFile + 4                                                             77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather                                                           77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteFileGather + 4                                                       77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory                                                        77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtWriteVirtualMemory + 4                                                    77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess                                                         77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] ntdll.dll!NtCreateUserProcess + 4                                                     77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] kernel32.dll!LoadLibraryExW                                                           765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExA                                                          77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\system32\Macromed\Flash\FlashUtil10h_ActiveX.exe[6376] USER32.dll!SetWindowsHookExW                                                          77B487AD 6 Bytes  JMP 5F3B0F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose                                                                                       77A74314 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtClose + 4                                                                                   77A74318 2 Bytes  [35, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile                                                                                  77A743D4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateFile + 4                                                                              77A743D8 2 Bytes  [17, 5F] {POP SS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey                                                                                   77A74414 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateKey + 4                                                                               77A74418 2 Bytes  [05, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess                                                                               77A74494 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcess + 4                                                                           77A74498 2 Bytes  [29, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx                                                                             77A744A4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateProcessEx + 4                                                                         77A744A8 2 Bytes  [2C, 5F] {SUB AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection                                                                               77A744C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateSection + 4                                                                           77A744C8 2 Bytes  [23, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey                                                                                   77A747C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteKey + 4                                                                               77A747C8 2 Bytes  [0B, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey                                                                              77A747F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtDeleteValueKey + 4                                                                          77A747F8 2 Bytes  [11, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey                                                                                   77A750C4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtRenameKey + 4                                                                               77A750C8 2 Bytes  [14, 5F] {ADC AL, 0x5f}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile                                                                          77A752E4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetInformationFile + 4                                                                      77A752E8 2 Bytes  [20, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey                                                                                 77A75454 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtSetValueKey + 4                                                                             77A75458 2 Bytes  [0E, 5F] {PUSH CS; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess                                                                            77A754F4 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtTerminateProcess + 4                                                                        77A754F8 2 Bytes  [2F, 5F] {DAS ; POP EDI}
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile                                                                                   77A75644 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFile + 4                                                                               77A75648 2 Bytes  [1A, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather                                                                             77A75654 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteFileGather + 4                                                                         77A75658 2 Bytes  [1D, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory                                                                          77A75674 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtWriteVirtualMemory + 4                                                                      77A75678 2 Bytes  [32, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess                                                                           77A75804 3 Bytes  [FF, 25, 1E]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] ntdll.dll!NtCreateUserProcess + 4                                                                       77A75808 2 Bytes  [26, 5F]
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] kernel32.dll!LoadLibraryExW                                                                             765F9109 5 Bytes  JMP 5F070F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExA                                                                            77B46322 6 Bytes  JMP 5F370F5A
    .text           C:\Windows\servicing\TrustedInstaller.exe[6940] USER32.dll!SetWindowsHookExW                                                                            77B487AD 6 Bytes  JMP 5F3B0F5A

    ---- User IAT/EAT - GMER 1.0.15 ----

    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcessHeap]          00C0E660
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]          00C0E140
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DuplicateHandle]         00C0D2A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!IsDebuggerPresent]       00C0EBE0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateThread]            00C0C260
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]          00C0BBD0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetEnvironmentStringsW]  00C0BF90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SetFilePointer]          00C0D100
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFileEx]         00C0D7C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileMappingW]      00C0D550
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!MapViewOfFile]           00C0D740
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!OpenFileMappingW]        00C0DC20
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!UnmapViewOfFile]         00C0D930
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileType]             00C0D450
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FlushViewOfFile]         00C0D690
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileSize]             00C0D240
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!WriteFile]               00C0D0C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetACP]                  00C0E680
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!TerminateProcess]        00C0C110
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalAlloc]             00C0E3A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalLock]              00C0E2C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GlobalUnlock]            00C0E280
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]             00C0C940
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]            00C0BA30
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CloseHandle]             00C0D340
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]            00C0B9A0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FreeLibrary]             00C0BC80
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetProcAddress]          00C0A730
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!ReadFile]                00C0CC90
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetVersion]              00C0E650
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadIconW]                 00C0E920
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadCursorW]               00C0E8C0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!CreateDialogParamW]        00C0EB10
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!DialogBoxParamW]           00C0EBB0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [USER32.dll!LoadStringW]               00C0E9E0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]          00C0E5D0
    IAT             c:\ProgramData\SingleClick Systems\Advanced Networking Service\hnm_svc.exe[1676] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]         00C0E580
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusShutdown]                                                                   [752C7817] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCloneImage]                                                                    [7531A86D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDrawImageRectI]                                                                [752CBB22] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetInterpolationMode]                                                          [752BF695] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdiplusStartup]                                                                    [752C75E9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateFromHDC]                                                                 [752BE7CA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStreamICM]                                                     [752F8395] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipCreateBitmapFromStream]                                                        [752CDA60] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageHeight]                                                                [752BFFFA] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipGetImageWidth]                                                                 [752BFF61] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDisposeImage]                                                                  [752B71CF] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFileICM]                                                          [7534CAE2] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipLoadImageFromFile]                                                             [752EC8D8] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipDeleteGraphics]                                                                [752BD968] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipFree]                                                                          [752B6853] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipAlloc]                                                                         [752B687E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Windows\Explorer.EXE[2740] @ C:\Windows\Explorer.EXE [gdiplus.dll!GdipSetCompositingMode]                                                            [752C2AD1] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\gdiplus.dll (Microsoft GDI+/Microsoft Corporation)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsSvc.exe[2924] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                    [0044A958] C:\Program Files\Spyware Doctor\pctsSvc.exe (PC Tools Security Service/PC Tools)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CopyFileW]                                          [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SearchPathW]                                       [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                    [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CopyFileW]                                         [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!WritePrivateProfileStringW]                        [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetPrivateProfileStringW]                          [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                  [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegEnumValueW]                                     [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegOpenKeyExW]                                     [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegQueryValueExW]                                  [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegDeleteKeyW]                                     [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCreateKeyExW]                                   [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\USER32.dll [ADVAPI32.dll!RegCloseKey]                                       [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindClose]                                         [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileA]                                    [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileA]                                     [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindFirstFileW]                                    [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!FindNextFileW]                                     [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA]                                [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryA]                              [63BCEBFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesA]                                [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryA]                                  [63BCE3CB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryA]                                  [63BCE9A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA]                                       [63BCC1D6] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW]                                [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetCurrentDirectoryW]                              [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!SetFileAttributesW]                                [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateDirectoryW]                                  [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW]                                       [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileW]                                         [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!RemoveDirectoryW]                                  [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!MoveFileA]                                         [63BCDDDD] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryA]                                      [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileA]                                       [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!CreateFileW]                                       [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\msvcrt.dll [KERNEL32.dll!LoadLibraryW]                                      [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetPrivateProfileStringA]                         [63BCA819] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SetFileAttributesA]                               [63BC8C26] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!CreateFileA]                                      [63BCBBD2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindFirstFileA]                                   [63BCFF42] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindNextFileA]                                    [63BCFB96] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!SearchPathA]                                      [63BCEFA8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!WinHelpA]                                           [63BCCE2E] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExA]                                  [63BDC49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyA]                                    [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyExA]                                    [63BDDFE1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumValueA]                                    [63BDE2F1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegEnumKeyA]                                      [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHLWAPI.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionW]                        [63BCA460] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindNextFileW]                                    [63BCFC09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!ReplaceFileW]                                     [63BCE151] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileSectionNamesW]                   [63BCA6E2] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileSectionW]                      [63BCAE92] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!WritePrivateProfileStringW]                       [63BCB114] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateHardLinkW]                                  [63BCC023] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetCurrentDirectoryW]                             [63BCF49D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CopyFileW]                                        [63BCB6A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetBinaryTypeW]                                   [63BC9700] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                   [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileW]                                        [63BCDE50] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindFirstFileW]                                   [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!FindClose]                                        [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameA]                                [63BC9362] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA]                               [63BC89D0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SearchPathW]                                      [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileIntW]                            [63BCA1D8] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetPrivateProfileStringW]                         [63BCA970] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!RemoveDirectoryW]                                 [63BCEAD0] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateDirectoryW]                                 [63BCE4F9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW]                                      [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!SetFileAttributesW]                               [63BC8D54] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW]                               [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW]                                      [63BCDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetShortPathNameW]                                [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                     [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!CreateFileW]                                      [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW]                             [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                     [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetLongPathNameW]                                 [63BC9231] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!LoadImageW]                                         [63BCC58B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!WinHelpW]                                           [63BCCF65] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [USER32.dll!PrivateExtractIconsW]                               [63BCCA80] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExW]                                    [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW]                                  [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyW]                                      [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumValueW]                                    [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteKeyW]                                    [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                 [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                 [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegEnumKeyExW]                                    [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW]                                     [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExW]                                 [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueW]                                   [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyW]                                      [63BDC8E9] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW]                                    [63BDC35D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegQueryValueExA]                                 [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA]                                    [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCloseKey]                                      [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\SHELL32.dll [ntdll.dll!NtQueryDirectoryFile]                                [63BD91AC] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindClose]                                          [63BD0D4C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!FindFirstFileW]                                     [63BD02A5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryExW]                                     [63BCD537] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!SearchPathW]                                        [63BCF233] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!DeleteFileW]                                        [63BCC301] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetShortPathNameW]                                  [63BC94A1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW]                               [63BC8FC1] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!CreateFileW]                                        [63BCBD1B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryW]                                       [63BCD221] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW]                                 [63BC8AFB] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [KERNEL32.dll!LoadLibraryA]                                       [63BCD09C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegSetValueW]                                       [63BDD13F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueA]                                     [63BDD28F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyExW]                                      [63BDE169] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumValueW]                                      [63BDE479] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyA]                                        [63BDDD0B] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyA]                                      [63BDCD5C] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyW]                                   [63BDDB0F] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryInfoKeyA]                                   [63BDD913] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueW]                                     [63BDD437] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegEnumKeyW]                                        [63BDDE75] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCloseKey]                                        [63BDCD09] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExW]                                   [63BDD773] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExW]                                      [63BDCB9D] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegDeleteKeyW]                                      [63BDCEA5] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegCreateKeyExW]                                    [63BDC625] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegQueryValueExA]                                   [63BDD5D3] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Internet Explorer\iexplore.exe[4392] @ C:\Windows\system32\ole32.dll [ADVAPI32.dll!RegOpenKeyExA]                                      [63BDCA25] C:\Windows\AppPatch\AcRedir.DLL (Windows Compatibility DLL/Microsoft Corporation)
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryExW]                                    [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryA]                                      [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!GetProcAddress]                                    [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\GDI32.dll [KERNEL32.dll!LoadLibraryW]                                      [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryExW]                                   [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryA]                                     [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!LoadLibraryW]                                     [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [KERNEL32.dll!GetProcAddress]                                   [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\USER32.dll [GDI32.dll!GetStockObject]                                      [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHLWAPI.dll [USER32.dll!DefWindowProcA]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryExW]                                  [6144AE77] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress]                                  [6144A7A3] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryW]                                    [6144ADE9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [KERNEL32.dll!LoadLibraryA]                                    [6144ADA9] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [GDI32.dll!GetStockObject]                                     [61449CEC] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenuEx]                                  [61449B94] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!TrackPopupMenu]                                    [61449B56] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColorBrush]                                  [61449CF2] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!GetSysColor]                                       [61449C27] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!DefWindowProcW]                                    [6144A3BA] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe[4460] @ C:\Windows\system32\SHELL32.dll [USER32.dll!AnimateWindow]                                     [61449D87] C:\Program Files\Yahoo!\Messenger\yui.dll
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\shell32.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)
    IAT             C:\Program Files\Spyware Doctor\pctsTray.exe[5020] @ C:\Windows\system32\SHLWAPI.dll [KERNEL32.dll!QueueUserWorkItem]                                   [0044A96C] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools Tray Application/PC Tools)

    ---- Devices - GMER 1.0.15 ----

    AttachedDevice  \Driver\tdx \Device\Tcp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\Udp                                                                                                                                 pctfw2.sys
    AttachedDevice  \Driver\tdx \Device\RawIp                                                                                                                               pctfw2.sys
    AttachedDevice  \FileSystem\fastfat \Fat                                                                                                                                fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)

    ---- Registry - GMER 1.0.15 ----

    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39                                                                            
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                0x9B 0x4D 0xE1 0x7E ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39 (not active ControlSet)                                                        
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0021866fd073                                                                    0x04 0x54 0xB1 0x24 ...
    Reg             HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\002269bffc39@0024044bf959                                                                    0x9B 0x4D 0xE1 0x7E ...

    ---- EOF - GMER 1.0.15 ----