Při startu dnes ráno jsem s počítačem nic nedělal, normálně naběhl, pak jsem hnul myší, načež zmizely skoro všechny ikony na ploše a OS se zasekl. Vytváření druhého logu trvá mnohem víc než v návodu uvedených 10 minut, po hodině a půl jsem byl donucen ho stopnout. Logy nemůžu připojit jako přílohu, budu to muset vložit do tří postů.
GMER 1.0.15.15281 - 
http://www.gmer.net
Rootkit quick scan 2010-04-24 12:26:17
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JANHRU~1\LOCALS~1\Temp\uxtdipoc.sys
---- Devices - GMER 1.0.15 ----
AttachedDevice  \Driver\Tcpip \Device\Ip     cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\Ip     aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp    aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Tcp    cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\Udp    aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
AttachedDevice  \Driver\Tcpip \Device\Udp    cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\RawIp  cmdhlp.sys (COMODO Internet Security Helper Driver/COMODO)
AttachedDevice  \Driver\Tcpip \Device\RawIp  aswTdi.SYS (avast! TDI Filter Driver/ALWIL Software)
---- EOF - GMER 1.0.15 ----
GMER 1.0.15.15281 - 
http://www.gmer.net
Rootkit scan 2010-04-24 13:53:20
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\JANHRU~1\LOCALS~1\Temp\uxtdipoc.sys
---- User code sections - GMER 1.0.15 ----
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtAllocateVirtualMemory                                                                           7C90CF6E 5 Bytes  JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtClose                                                                                           7C90CFEE 5 Bytes  JMP 100082B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtCreateFile                                                                                      7C90D0AE 5 Bytes  JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtCreateProcess                                                                                   7C90D14E 5 Bytes  JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtCreateProcessEx                                                                                 7C90D15E 5 Bytes  JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtDeleteFile                                                                                      7C90D23E 5 Bytes  JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtFreeVirtualMemory                                                                               7C90D38E 5 Bytes  JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtLoadDriver                                                                                      7C90D46E 5 Bytes  JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtOpenFile                                                                                        7C90D59E 5 Bytes  JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtProtectVirtualMemory                                                                            7C90D6EE 5 Bytes  JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtSetInformationProcess                                                                           7C90DC9E 5 Bytes  JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtUnloadDriver                                                                                    7C90DEBE 5 Bytes  JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!NtWriteVirtualMemory                                                                              7C90DFAE 5 Bytes  JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!RtlAllocateHeap                                                                                   7C9100C4 5 Bytes  JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!LdrLoadDll                                                                                        7C9163C3 5 Bytes  JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!LdrUnloadDll                                                                                      7C91738B 5 Bytes  JMP 100081E0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ntdll.dll!LdrGetProcedureAddress                                                                            7C917EA8 5 Bytes  JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CreateFileA                                                                                    7C801A28 5 Bytes  JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!VirtualProtect                                                                                 7C801AD4 5 Bytes  JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadLibraryExW                                                                                 7C801AF5 7 Bytes  JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadLibraryExA                                                                                 7C801D53 5 Bytes  JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadLibraryA                                                                                   7C801D7B 5 Bytes  JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CreateProcessW                                                                                 7C802336 5 Bytes  JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CreateProcessA                                                                                 7C80236B 5 Bytes  JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!GetProcAddress                                                                                 7C80AE40 5 Bytes  JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadLibraryW                                                                                   7C80AEEB 5 Bytes  JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!GetModuleHandleA                                                                               7C80B741 5 Bytes  JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!GetModuleHandleW                                                                               7C80E4DD 5 Bytes  JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CreateFileW                                                                                    7C810800 5 Bytes  JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileWithProgressW                                                                          7C81F72E 5 Bytes  JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileW                                                                                      7C821261 5 Bytes  JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!OpenFile                                                                                       7C821982 2 Bytes  JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!OpenFile + 3                                                                                   7C821985 2 Bytes  [7E, 93] {JLE 0xffffffffffffff95}
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CopyFileExW                                                                                    7C827B32 7 Bytes  JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CopyFileA                                                                                      7C8286EE 5 Bytes  JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CopyFileW                                                                                      7C82F87B 5 Bytes  JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!DeleteFileA                                                                                    7C831EDD 5 Bytes  JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!DeleteFileW                                                                                    7C831F63 5 Bytes  JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileExW                                                                                    7C83568B 5 Bytes  JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileA                                                                                      7C835EBF 5 Bytes  JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileWithProgressA                                                                          7C835EDE 5 Bytes  JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!MoveFileExA                                                                                    7C85E49B 5 Bytes  JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!CopyFileExA                                                                                    7C85F39C 5 Bytes  JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!WinExec                                                                                        7C86250D 5 Bytes  JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] kernel32.dll!LoadModule                                                                                     7C86261E 5 Bytes  JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ADVAPI32.dll!OpenServiceW                                                                                   77DD6FFD 7 Bytes  JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ADVAPI32.dll!OpenServiceA                                                                                   77DE4C66 7 Bytes  JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ADVAPI32.dll!CreateServiceA                                                                                 77E27211 7 Bytes  JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] ADVAPI32.dll!CreateServiceW                                                                                 77E273A9 7 Bytes  JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] USER32.dll!EndTask                                                                                          7E3AA0A5 5 Bytes  JMP 10007E80 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!WSASocketW                                                                                       71A9404E 7 Bytes  JMP 10001E90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\winlogon.exe[640] WS2_32.dll!WSASocketA                                                                                       71A98B6A 5 Bytes  JMP 10001E70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtAllocateVirtualMemory                                                                           7C90CF6E 5 Bytes  JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtClose                                                                                           7C90CFEE 5 Bytes  JMP 100082B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtCreateFile                                                                                      7C90D0AE 5 Bytes  JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtCreateProcess                                                                                   7C90D14E 5 Bytes  JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtCreateProcessEx                                                                                 7C90D15E 5 Bytes  JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtDeleteFile                                                                                      7C90D23E 5 Bytes  JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtFreeVirtualMemory                                                                               7C90D38E 5 Bytes  JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtLoadDriver                                                                                      7C90D46E 5 Bytes  JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtOpenFile                                                                                        7C90D59E 5 Bytes  JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtProtectVirtualMemory                                                                            7C90D6EE 5 Bytes  JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtSetInformationProcess                                                                           7C90DC9E 5 Bytes  JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtUnloadDriver                                                                                    7C90DEBE 5 Bytes  JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!NtWriteVirtualMemory                                                                              7C90DFAE 5 Bytes  JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!RtlAllocateHeap                                                                                   7C9100C4 5 Bytes  JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!LdrLoadDll                                                                                        7C9163C3 5 Bytes  JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!LdrUnloadDll                                                                                      7C91738B 5 Bytes  JMP 100081E0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ntdll.dll!LdrGetProcedureAddress                                                                            7C917EA8 5 Bytes  JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CreateFileA                                                                                    7C801A28 5 Bytes  JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!VirtualProtect                                                                                 7C801AD4 5 Bytes  JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadLibraryExW                                                                                 7C801AF5 7 Bytes  JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadLibraryExA                                                                                 7C801D53 5 Bytes  JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadLibraryA                                                                                   7C801D7B 5 Bytes  JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CreateProcessW                                                                                 7C802336 5 Bytes  JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CreateProcessA                                                                                 7C80236B 5 Bytes  JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!GetProcAddress                                                                                 7C80AE40 5 Bytes  JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadLibraryW                                                                                   7C80AEEB 5 Bytes  JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!GetModuleHandleA                                                                               7C80B741 5 Bytes  JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!GetModuleHandleW                                                                               7C80E4DD 5 Bytes  JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CreateFileW                                                                                    7C810800 5 Bytes  JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileWithProgressW                                                                          7C81F72E 5 Bytes  JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileW                                                                                      7C821261 5 Bytes  JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!OpenFile                                                                                       7C821982 2 Bytes  JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!OpenFile + 3                                                                                   7C821985 2 Bytes  [7E, 93] {JLE 0xffffffffffffff95}
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CopyFileExW                                                                                    7C827B32 7 Bytes  JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CopyFileA                                                                                      7C8286EE 5 Bytes  JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CopyFileW                                                                                      7C82F87B 5 Bytes  JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!DeleteFileA                                                                                    7C831EDD 5 Bytes  JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!DeleteFileW                                                                                    7C831F63 5 Bytes  JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileExW                                                                                    7C83568B 5 Bytes  JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileA                                                                                      7C835EBF 5 Bytes  JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileWithProgressA                                                                          7C835EDE 5 Bytes  JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!MoveFileExA                                                                                    7C85E49B 5 Bytes  JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!CopyFileExA                                                                                    7C85F39C 5 Bytes  JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!WinExec                                                                                        7C86250D 5 Bytes  JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] kernel32.dll!LoadModule                                                                                     7C86261E 5 Bytes  JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ADVAPI32.dll!OpenServiceW                                                                                   77DD6FFD 7 Bytes  JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ADVAPI32.dll!OpenServiceA                                                                                   77DE4C66 7 Bytes  JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ADVAPI32.dll!CreateServiceA                                                                                 77E27211 7 Bytes  JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] ADVAPI32.dll!CreateServiceW                                                                                 77E273A9 7 Bytes  JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\services.exe[684] USER32.dll!EndTask                                                                                          7E3AA0A5 5 Bytes  JMP 10007E80 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtAllocateVirtualMemory                                                                              7C90CF6E 5 Bytes  JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtClose                                                                                              7C90CFEE 5 Bytes  JMP 100082B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtCreateFile                                                                                         7C90D0AE 5 Bytes  JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtCreateProcess                                                                                      7C90D14E 5 Bytes  JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtCreateProcessEx                                                                                    7C90D15E 5 Bytes  JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtDeleteFile                                                                                         7C90D23E 5 Bytes  JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtFreeVirtualMemory                                                                                  7C90D38E 5 Bytes  JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtLoadDriver                                                                                         7C90D46E 5 Bytes  JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtOpenFile                                                                                           7C90D59E 5 Bytes  JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtProtectVirtualMemory                                                                               7C90D6EE 5 Bytes  JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtSetInformationProcess                                                                              7C90DC9E 5 Bytes  JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtUnloadDriver                                                                                       7C90DEBE 5 Bytes  JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!NtWriteVirtualMemory                                                                                 7C90DFAE 5 Bytes  JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!RtlAllocateHeap                                                                                      7C9100C4 5 Bytes  JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!LdrLoadDll                                                                                           7C9163C3 5 Bytes  JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!LdrUnloadDll                                                                                         7C91738B 5 Bytes  JMP 100081E0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ntdll.dll!LdrGetProcedureAddress                                                                               7C917EA8 5 Bytes  JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CreateFileA                                                                                       7C801A28 5 Bytes  JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!VirtualProtect                                                                                    7C801AD4 5 Bytes  JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadLibraryExW                                                                                    7C801AF5 7 Bytes  JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadLibraryExA                                                                                    7C801D53 5 Bytes  JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadLibraryA                                                                                      7C801D7B 5 Bytes  JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CreateProcessW                                                                                    7C802336 5 Bytes  JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CreateProcessA                                                                                    7C80236B 5 Bytes  JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!GetProcAddress                                                                                    7C80AE40 5 Bytes  JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadLibraryW                                                                                      7C80AEEB 5 Bytes  JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!GetModuleHandleA                                                                                  7C80B741 5 Bytes  JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!GetModuleHandleW                                                                                  7C80E4DD 5 Bytes  JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CreateFileW                                                                                       7C810800 5 Bytes  JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileWithProgressW                                                                             7C81F72E 5 Bytes  JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileW                                                                                         7C821261 5 Bytes  JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!OpenFile                                                                                          7C821982 2 Bytes  JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!OpenFile + 3                                                                                      7C821985 2 Bytes  [7E, 93] {JLE 0xffffffffffffff95}
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CopyFileExW                                                                                       7C827B32 7 Bytes  JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CopyFileA                                                                                         7C8286EE 5 Bytes  JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CopyFileW                                                                                         7C82F87B 5 Bytes  JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!DeleteFileA                                                                                       7C831EDD 5 Bytes  JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!DeleteFileW                                                                                       7C831F63 5 Bytes  JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileExW                                                                                       7C83568B 5 Bytes  JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileA                                                                                         7C835EBF 5 Bytes  JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileWithProgressA                                                                             7C835EDE 5 Bytes  JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!MoveFileExA                                                                                       7C85E49B 5 Bytes  JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!CopyFileExA                                                                                       7C85F39C 5 Bytes  JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!WinExec                                                                                           7C86250D 5 Bytes  JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] kernel32.dll!LoadModule                                                                                        7C86261E 5 Bytes  JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ADVAPI32.dll!OpenServiceW                                                                                      77DD6FFD 7 Bytes  JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ADVAPI32.dll!OpenServiceA                                                                                      77DE4C66 7 Bytes  JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ADVAPI32.dll!CreateServiceA                                                                                    77E27211 7 Bytes  JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ADVAPI32.dll!CreateServiceW                                                                                    77E273A9 7 Bytes  JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] USER32.dll!EndTask                                                                                             7E3AA0A5 5 Bytes  JMP 10007E80 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!WSASocketW                                                                                          71A9404E 7 Bytes  JMP 10001E90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] WS2_32.dll!WSASocketA                                                                                          71A98B6A 5 Bytes  JMP 10001E70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ole32.dll!CoCreateInstanceEx                                                                                   774F0526 5 Bytes  JMP 10007BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] ole32.dll!CoGetClassObject                                                                                     775056C5 5 Bytes  JMP 10007D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] SHELL32.dll!ShellExecuteExW                                                                                    7CA0996B 5 Bytes  JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] SHELL32.dll!ShellExecuteEx                                                                                     7CA40EB5 5 Bytes  JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] SHELL32.dll!ShellExecuteA                                                                                      7CA411E0 5 Bytes  JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\lsass.exe[696] SHELL32.dll!ShellExecuteW                                                                                      7CAB5D48 5 Bytes  JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtAllocateVirtualMemory                                                                            7C90CF6E 5 Bytes  JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtClose                                                                                            7C90CFEE 5 Bytes  JMP 100082B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtCreateFile                                                                                       7C90D0AE 5 Bytes  JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtCreateProcess                                                                                    7C90D14E 5 Bytes  JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtCreateProcessEx                                                                                  7C90D15E 5 Bytes  JMP 100019B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtDeleteFile                                                                                       7C90D23E 5 Bytes  JMP 10001910 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtFreeVirtualMemory                                                                                7C90D38E 5 Bytes  JMP 10001A30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtLoadDriver                                                                                       7C90D46E 5 Bytes  JMP 10001970 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtOpenFile                                                                                         7C90D59E 5 Bytes  JMP 100018F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtProtectVirtualMemory                                                                             7C90D6EE 5 Bytes  JMP 10001930 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtSetInformationProcess                                                                            7C90DC9E 5 Bytes  JMP 100019D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtUnloadDriver                                                                                     7C90DEBE 5 Bytes  JMP 10001990 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!NtWriteVirtualMemory                                                                               7C90DFAE 5 Bytes  JMP 100018B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!RtlAllocateHeap                                                                                    7C9100C4 5 Bytes  JMP 10001A10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!LdrLoadDll                                                                                         7C9163C3 5 Bytes  JMP 10004550 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!LdrUnloadDll                                                                                       7C91738B 5 Bytes  JMP 100081E0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ntdll.dll!LdrGetProcedureAddress                                                                             7C917EA8 5 Bytes  JMP 100019F0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateFileA                                                                                     7C801A28 5 Bytes  JMP 10001B30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!VirtualProtect                                                                                  7C801AD4 5 Bytes  JMP 10001D90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadLibraryExW                                                                                  7C801AF5 7 Bytes  JMP 10001AF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadLibraryExA                                                                                  7C801D53 5 Bytes  JMP 10001AD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadLibraryA                                                                                    7C801D7B 5 Bytes  JMP 10001D30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessW                                                                                  7C802336 5 Bytes  JMP 10001A70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateProcessA                                                                                  7C80236B 5 Bytes  JMP 10001A50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!GetProcAddress                                                                                  7C80AE40 5 Bytes  JMP 10001A90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadLibraryW                                                                                    7C80AEEB 5 Bytes  JMP 10001D50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!GetModuleHandleA                                                                                7C80B741 5 Bytes  JMP 10001CF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!GetModuleHandleW                                                                                7C80E4DD 5 Bytes  JMP 10001D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CreateFileW                                                                                     7C810800 5 Bytes  JMP 10001B50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileWithProgressW                                                                           7C81F72E 5 Bytes  JMP 10001C90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileW                                                                                       7C821261 5 Bytes  JMP 10001C10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!OpenFile                                                                                        7C821982 2 Bytes  JMP 10001B10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!OpenFile + 3                                                                                    7C821985 2 Bytes  [7E, 93] {JLE 0xffffffffffffff95}
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CopyFileExW                                                                                     7C827B32 7 Bytes  JMP 10001BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CopyFileA                                                                                       7C8286EE 5 Bytes  JMP 10001B70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CopyFileW                                                                                       7C82F87B 5 Bytes  JMP 10001B90 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!DeleteFileA                                                                                     7C831EDD 5 Bytes  JMP 10001CB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!DeleteFileW                                                                                     7C831F63 5 Bytes  JMP 10001CD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileExW                                                                                     7C83568B 5 Bytes  JMP 10001C50 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileA                                                                                       7C835EBF 5 Bytes  JMP 10001BF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileWithProgressA                                                                           7C835EDE 5 Bytes  JMP 10001C70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!MoveFileExA                                                                                     7C85E49B 5 Bytes  JMP 10001C30 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!CopyFileExA                                                                                     7C85F39C 5 Bytes  JMP 10001BB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!WinExec                                                                                         7C86250D 5 Bytes  JMP 10001D70 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] kernel32.dll!LoadModule                                                                                      7C86261E 5 Bytes  JMP 10001AB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!OpenServiceW                                                                                    77DD6FFD 7 Bytes  JMP 10001480 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!OpenServiceA                                                                                    77DE4C66 7 Bytes  JMP 10001640 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!CreateServiceA                                                                                  77E27211 7 Bytes  JMP 10001000 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ADVAPI32.dll!CreateServiceW                                                                                  77E273A9 7 Bytes  JMP 10001250 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] USER32.dll!EndTask                                                                                           7E3AA0A5 5 Bytes  JMP 10007E80 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ole32.dll!CoCreateInstanceEx                                                                                 774F0526 5 Bytes  JMP 10007BD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] ole32.dll!CoGetClassObject                                                                                   775056C5 5 Bytes  JMP 10007D10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] SHELL32.dll!ShellExecuteExW                                                                                  7CA0996B 5 Bytes  JMP 10001E10 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] SHELL32.dll!ShellExecuteEx                                                                                   7CA40EB5 5 Bytes  JMP 10001DF0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] SHELL32.dll!ShellExecuteA                                                                                    7CA411E0 5 Bytes  JMP 10001DB0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[868] SHELL32.dll!ShellExecuteW                                                                                    7CAB5D48 5 Bytes  JMP 10001DD0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtAllocateVirtualMemory                                                                            7C90CF6E 5 Bytes  JMP 10001950 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtClose                                                                                            7C90CFEE 5 Bytes  JMP 100082B0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateFile                                                                                       7C90D0AE 5 Bytes  JMP 100018D0 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)
.text           C:\WINDOWS\system32\svchost.exe[936] ntdll.dll!NtCreateProcess                                                                                    7C90D14E 5 Bytes  JMP 10001890 C:\WINDOWS\system32\guard32.dll (COMODO Internet Security/COMODO)