.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 01880FCA
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01880058
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01880011
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01880FE5
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0188003D
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01880000
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01880FA5
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [A8, 89] {TEST AL, 0x89}
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0188002C
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01870051
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!system 77C293C7 5 Bytes JMP 01870FBC
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0187001B
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01870FEF
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0187002C
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01870000
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenA 3D95D688 5 Bytes JMP 01860FEF
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenW 3D95DB01 5 Bytes JMP 01860FD4
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlA 3D95F39C 5 Bytes JMP 01860014
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlW 3D9A6F37 5 Bytes JMP 01860025
.text C:\WINDOWS\Explorer.EXE[516] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02030FEF
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00060F94
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00060093
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00060078
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0006005B
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0006002F
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 000600DC
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 000600CB
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000600FE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000600ED
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0006010F
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00060040
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00060FDE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 000600AE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0006001E
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00060FC3
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00060F6F
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00050025
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00050076
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00050FD4
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00050FC3
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00050065
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00050040
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00040FB7
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!system 77C293C7 5 Bytes JMP 00040042
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00040027
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00040FD2
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wopen
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 01880058
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 01880011
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 01880FE5
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 0188003D
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 01880000
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW 77DFBA55 2 Bytes JMP 01880FA5
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyW + 3 77DFBA58 2 Bytes [A8, 89] {TEST AL, 0x89}
.text C:\WINDOWS\Explorer.EXE[516] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 0188002C
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 01870051
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!system 77C293C7 5 Bytes JMP 01870FBC
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 0187001B
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_open 77C2F566 5 Bytes JMP 01870FEF
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 0187002C
.text C:\WINDOWS\Explorer.EXE[516] msvcrt.dll!_wopen 77C30055 5 Bytes JMP 01870000
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenA 3D95D688 5 Bytes JMP 01860FEF
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenW 3D95DB01 5 Bytes JMP 01860FD4
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlA 3D95F39C 5 Bytes JMP 01860014
.text C:\WINDOWS\Explorer.EXE[516] WININET.dll!InternetOpenUrlW 3D9A6F37 5 Bytes JMP 01860025
.text C:\WINDOWS\Explorer.EXE[516] WS2_32.dll!socket 71AB4211 5 Bytes JMP 02030FEF
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileA 7C801A28 5 Bytes JMP 00060FEF
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtectEx 7C801A61 5 Bytes JMP 00060F94
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!VirtualProtect 7C801AD4 5 Bytes JMP 00060093
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExW 7C801AF5 5 Bytes JMP 00060078
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryExA 7C801D53 5 Bytes JMP 0006005B
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryA 7C801D7B 5 Bytes JMP 0006002F
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoW 7C801E54 5 Bytes JMP 000600DC
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetStartupInfoA 7C801EF2 5 Bytes JMP 000600CB
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 000600FE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 000600ED
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!GetProcAddress 7C80AE40 5 Bytes JMP 0006010F
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!LoadLibraryW 7C80AEEB 5 Bytes JMP 00060040
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateFileW 7C810800 5 Bytes JMP 00060FDE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreatePipe 7C81D83F 5 Bytes JMP 000600AE
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeW 7C82F0DD 5 Bytes JMP 0006001E
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!CreateNamedPipeA 7C860CDC 5 Bytes JMP 00060FC3
.text C:\WINDOWS\system32\services.exe[752] kernel32.dll!WinExec 7C86250D 5 Bytes JMP 00060F6F
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExW 77DD6AAF 5 Bytes JMP 00050025
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExW 77DD776C 5 Bytes JMP 00050076
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyExA 77DD7852 5 Bytes JMP 00050FD4
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyW 77DD7946 5 Bytes JMP 00050FEF
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyExA 77DDE9F4 5 Bytes JMP 00050FC3
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegOpenKeyA 77DDEFC8 5 Bytes JMP 00050000
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyW 77DFBA55 5 Bytes JMP 00050065
.text C:\WINDOWS\system32\services.exe[752] ADVAPI32.dll!RegCreateKeyA 77DFBCF3 5 Bytes JMP 00050040
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wsystem 77C2931E 5 Bytes JMP 00040FB7
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!system 77C293C7 5 Bytes JMP 00040042
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_creat 77C2D40F 5 Bytes JMP 00040027
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_open 77C2F566 5 Bytes JMP 00040000
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wcreat 77C2FC9B 5 Bytes JMP 00040FD2
.text C:\WINDOWS\system32\services.exe[752] msvcrt.dll!_wopen