[3384]svchost.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[3384]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[3384]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[3384]svchost.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[3384]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[3384]svchost.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[3384]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[3384]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3384]svchost.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3384]svchost.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA40F40-->00000000 [guard32.dll]
[3384]svchost.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40C15-->00000000 [guard32.dll]
[3384]svchost.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA01823-->00000000 [guard32.dll]
[3384]svchost.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB4FD0-->00000000 [guard32.dll]
[3384]svchost.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[3568]alg.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[3568]alg.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[3568]alg.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[3568]alg.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[3568]alg.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[3568]alg.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[3568]alg.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[3568]alg.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3568]alg.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3568]alg.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA40F40-->00000000 [guard32.dll]
[3568]alg.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40C15-->00000000 [guard32.dll]
[3568]alg.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA01823-->00000000 [guard32.dll]
[3568]alg.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB4FD0-->00000000 [guard32.dll]
[3568]alg.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[3568]alg.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8769-->00000000 [guard32.dll]
[3568]alg.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB39CB-->00000000 [guard32.dll]
[3568]alg.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D0 [unknown_code_page]
[3568]alg.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D1 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8769-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB39CB-->00000000 [guard32.dll]
[3668]AppleMobileDeviceService.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D0 [unknown_code_page]
[3668]AppleMobileDeviceService.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D1 [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[3788]jqs.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[3788]jqs.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[3788]jqs.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[3788]jqs.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[3788]jqs.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[3788]jqs.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[3788]jqs.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3788]jqs.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3788]jqs.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[3788]jqs.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8769-->00000000 [guard32.dll]
[3788]jqs.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB39CB-->00000000 [guard32.dll]
[3788]jqs.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D0 [unknown_code_page]
[3788]jqs.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB39D1 [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[4008]uphclean.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[4008]uphclean.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[4008]uphclean.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[4008]uphclean.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[4008]uphclean.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[4008]uphclean.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[4008]uphclean.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[4008]uphclean.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[4052]iPodService.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[4052]iPodService.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[4052]iPodService.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[4052]iPodService.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[4052]iPodService.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[4052]iPodService.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[4052]iPodService.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[4052]iPodService.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[4620]hpsysdrv.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[4620]hpsysdrv.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x7C80103C-->00000000 [LVPrcInj.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x7C801008-->00000000 [LVPrcInj.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x7C801038-->00000000 [LVPrcInj.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x7C8011BC-->00000000 [LVPrcInj.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[4620]hpsysdrv.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E109B0-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DF6285-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E370B9-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BE [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E370BF [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E37251-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37256 [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E37257 [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DEE2AE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B3 [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DEE2B4 [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE5F05-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0A [unknown_code_page]
[4752]RTHDCPL.EXE-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE5F0B [unknown_code_page]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286FE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85E554-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B42-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B47 [unknown_code_page]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B48 [unknown_code_page]
[4752]RTHDCPL.EXE-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F88F-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A24-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810770-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C802367-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802332-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EF5-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F7B-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B6B1-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E44D-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80ADB0-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D77-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D4F-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF1-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF6 [unknown_code_page]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AF7 [unknown_code_page]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AE5B-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86169E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835ED7-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85D653-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C8356A3-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821271-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EF6-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F73E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->ntdll.dll-->NtClose, Type: IAT modification 0x7C80103C-->00000000 [LVPrcInj.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->ntdll.dll-->NtCreateFile, Type: IAT modification 0x7C801008-->00000000 [LVPrcInj.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->ntdll.dll-->NtDeviceIoControlFile, Type: IAT modification 0x7C801038-->00000000 [LVPrcInj.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->ntdll.dll-->NtDuplicateObject, Type: IAT modification 0x7C8011BC-->00000000 [LVPrcInj.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821992-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD0-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86158D-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C919328-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C915CBB-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C916C83-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA40F40-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40C15-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA01823-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB4FD0-->00000000 [guard32.dll]
[4752]RTHDCPL.EXE-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E459E75-->00000000 [guard32.dll]