0000000077791510 5 bytes JMP 0000000149dd0370
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 0000000149dd0470
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 0000000149dd03e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 0000000149dd0320
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 0000000149dd03b0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 0000000149dd0390
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 0000000149dd02e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 0000000149dd02d0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 0000000149dd0310
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 0000000149dd03c0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 0000000149dd03f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 0000000149dd0230
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 0000000149dd0480
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 0000000149dd03a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 0000000149dd02f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 0000000149dd0350
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 0000000149dd0290
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 0000000149dd02b0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 0000000149dd03d0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 0000000149dd0330
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 0000000149dd0410
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 0000000149dd0240
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 0000000149dd01e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 0000000149dd0250
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 0000000149dd0490
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 0000000149dd04a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 0000000149dd0300
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 0000000149dd0360
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 0000000149dd02a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 0000000149dd02c0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 0000000149dd0380
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 0000000149dd0340
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 0000000149dd0440
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 0000000149dd0260
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 0000000149dd0270
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 0000000149dd0400
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 0000000149dd01f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 0000000149dd0210
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 0000000149dd0200
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 0000000149dd0420
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 0000000149dd0430
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 0000000149dd0220
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 0000000149dd0280
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 00000000778f0460
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 00000000778f0450
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 00000000778f0370
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 00000000778f0470
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000000778f03e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 00000000778f0320
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000000778f03b0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 00000000778f0390
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000000778f02e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000000778f02d0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 00000000778f0310
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000000778f03c0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000000778f03f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 00000000778f0230
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 00000000778f0480
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000000778f03a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000000778f02f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 00000000778f0350
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 00000000778f0290
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000000778f02b0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000000778f03d0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 00000000778f0330
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 00000000778f0410
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 00000000778f0240
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 00000000778f01e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 00000000778f0250
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 00000000778f0490
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 00000000778f04a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 00000000778f0300
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 00000000778f0360
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 00000000778f02a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 00000000778f02c0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 00000000778f0380
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 00000000778f0340
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 00000000778f0440
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 00000000778f0260
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 00000000778f0270
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 00000000778f0400
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 00000000778f01f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 00000000778f0210
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 00000000778f0200
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 00000000778f0420
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 00000000778f0430
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 00000000778f0220
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 00000000778f0280
.text C:\Windows\system32\wininit.exe[628] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189
000000007767ef8d 1 byte [62]
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 00000000778f0460
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 00000000778f0450
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 00000000778f0370
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 00000000778f0470
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000000778f03e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 00000000778f0320
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000000778f03b0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 00000000778f0390
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000000778f02e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000000778f02d0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 00000000778f0310
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000000778f03c0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000000778f03f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 00000000778f0230
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 00000000778f0480
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000000778f03a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000000778f02f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 00000000778f0350
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 00000000778f0290
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000000778f02b0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000000778f03d0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 00000000778f0330
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 00000000778f0410
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 00000000778f0240
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 00000000778f01e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 00000000778f0250
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 00000000778f0490
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 00000000778f04a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 00000000778f0300
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 00000000778f0360
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 00000000778f02a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 00000000778f02c0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 00000000778f0380
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 00000000778f0340
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 00000000778f0440
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 00000000778f0260
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 00000000778f0270
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 00000000778f0400
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 00000000778f01f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 00000000778f0210
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 00000000778f0200
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 00000000778f0420
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 00000000778f0430
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 00000000778f0220
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 00000000778f0280
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189
000000007767ef8d 1 byte [62]
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 0000000100070460
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 0000000100070450
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 0000000100070370
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 0000000100070470
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000001000703e0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 0000000100070320
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000001000703b0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 0000000100070390
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000001000702e0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000001000702d0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 0000000100070310
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000001000703c0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000001000703f0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 0000000100070230
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 0000000100070480
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000001000703a0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000001000702f0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 0000000100070350
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 0000000100070290
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000001000702b0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000001000703d0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 0000000100070330
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 0000000100070410
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 0000000100070240
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 0000000149dd0470
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 0000000149dd03e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 0000000149dd0320
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 0000000149dd03b0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 0000000149dd0390
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 0000000149dd02e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 0000000149dd02d0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 0000000149dd0310
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 0000000149dd03c0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 0000000149dd03f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 0000000149dd0230
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 0000000149dd0480
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 0000000149dd03a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 0000000149dd02f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 0000000149dd0350
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 0000000149dd0290
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 0000000149dd02b0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 0000000149dd03d0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 0000000149dd0330
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 0000000149dd0410
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 0000000149dd0240
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 0000000149dd01e0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 0000000149dd0250
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 0000000149dd0490
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 0000000149dd04a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 0000000149dd0300
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 0000000149dd0360
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 0000000149dd02a0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 0000000149dd02c0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 0000000149dd0380
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 0000000149dd0340
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 0000000149dd0440
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 0000000149dd0260
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 0000000149dd0270
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 0000000149dd0400
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 0000000149dd01f0
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 0000000149dd0210
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 0000000149dd0200
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 0000000149dd0420
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 0000000149dd0430
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 0000000149dd0220
.text C:\Windows\system32\csrss.exe[620] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 0000000149dd0280
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 00000000778f0460
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 00000000778f0450
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 00000000778f0370
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 00000000778f0470
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000000778f03e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 00000000778f0320
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000000778f03b0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 00000000778f0390
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000000778f02e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000000778f02d0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 00000000778f0310
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000000778f03c0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000000778f03f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 00000000778f0230
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 00000000778f0480
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000000778f03a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000000778f02f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 00000000778f0350
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 00000000778f0290
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000000778f02b0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000000778f03d0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 00000000778f0330
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 00000000778f0410
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 00000000778f0240
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 00000000778f01e0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 00000000778f0250
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 00000000778f0490
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 00000000778f04a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 00000000778f0300
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 00000000778f0360
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 00000000778f02a0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 00000000778f02c0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 00000000778f0380
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 00000000778f0340
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 00000000778f0440
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 00000000778f0260
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 00000000778f0270
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 00000000778f0400
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 00000000778f01f0
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 00000000778f0210
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 00000000778f0200
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 00000000778f0420
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 00000000778f0430
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 00000000778f0220
.text C:\Windows\system32\wininit.exe[628] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 00000000778f0280
.text C:\Windows\system32\wininit.exe[628] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189
000000007767ef8d 1 byte [62]
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 00000000778f0460
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 00000000778f0450
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 00000000778f0370
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 00000000778f0470
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000000778f03e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 00000000778f0320
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000000778f03b0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 00000000778f0390
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000000778f02e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000000778f02d0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 00000000778f0310
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000000778f03c0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000000778f03f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 00000000778f0230
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 00000000778f0480
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000000778f03a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000000778f02f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 00000000778f0350
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 00000000778f0290
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000000778f02b0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000000778f03d0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 00000000778f0330
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 00000000778f0410
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 00000000778f0240
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver
00000000777920a0 5 bytes JMP 00000000778f01e0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry
0000000077792160 5 bytes JMP 00000000778f0250
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey
0000000077792190 5 bytes JMP 00000000778f0490
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys
00000000777921a0 5 bytes JMP 00000000778f04a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair
00000000777921d0 5 bytes JMP 00000000778f0300
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion
00000000777921e0 5 bytes JMP 00000000778f0360
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant
0000000077792240 5 bytes JMP 00000000778f02a0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore
0000000077792290 5 bytes JMP 00000000778f02c0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread
00000000777922c0 5 bytes JMP 00000000778f0380
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer
00000000777922d0 5 bytes JMP 00000000778f0340
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx
00000000777925c0 5 bytes JMP 00000000778f0440
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder
00000000777927c0 5 bytes JMP 00000000778f0260
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions
00000000777927d0 5 bytes JMP 00000000778f0270
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread
00000000777927e0 5 bytes JMP 00000000778f0400
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation
00000000777929a0 5 bytes JMP 00000000778f01f0
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState
00000000777929b0 5 bytes JMP 00000000778f0210
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem
0000000077792a20 5 bytes JMP 00000000778f0200
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess
0000000077792a80 5 bytes JMP 00000000778f0420
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread
0000000077792a90 5 bytes JMP 00000000778f0430
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl
0000000077792aa0 5 bytes JMP 00000000778f0220
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl
0000000077792b80 5 bytes JMP 00000000778f0280
.text C:\Windows\system32\winlogon.exe[676] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189
000000007767ef8d 1 byte [62]
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort
0000000077791360 5 bytes JMP 0000000100070460
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject
00000000777913b0 5 bytes JMP 0000000100070450
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess
0000000077791510 5 bytes JMP 0000000100070370
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx
0000000077791560 5 bytes JMP 0000000100070470
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess
0000000077791570 5 bytes JMP 00000001000703e0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection
0000000077791620 5 bytes JMP 0000000100070320
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory
0000000077791650 5 bytes JMP 00000001000703b0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject
0000000077791670 5 bytes JMP 0000000100070390
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent
00000000777916b0 5 bytes JMP 00000001000702e0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent
0000000077791730 5 bytes JMP 00000001000702d0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection
0000000077791750 5 bytes JMP 0000000100070310
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread
0000000077791790 5 bytes JMP 00000001000703c0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread
00000000777917e0 5 bytes JMP 00000001000703f0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry
0000000077791940 5 bytes JMP 0000000100070230
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort
0000000077791b00 5 bytes JMP 0000000100070480
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject
0000000077791b30 5 bytes JMP 00000001000703a0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair
0000000077791c10 5 bytes JMP 00000001000702f0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion
0000000077791c20 5 bytes JMP 0000000100070350
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant
0000000077791c80 5 bytes JMP 0000000100070290
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore
0000000077791d10 5 bytes JMP 00000001000702b0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx
0000000077791d30 5 bytes JMP 00000001000703d0
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer
0000000077791d40 5 bytes JMP 0000000100070330
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess
0000000077791db0 5 bytes JMP 0000000100070410
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry
0000000077791de0 5 bytes JMP 0000000100070240
.text C:\Windows\system32\services.exe[728] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver