[2700]postgres.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2700]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[2712]svchost.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2736]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2780]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - RelativeJump 0x7C810E27-->00000000 [mssrch.dll]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page]
[3168]searchindexer.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[3168]searchindexer.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[332]ehSched.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[3380]orca.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3380]orca.exe-->wininet.dll-->InternetConnectA, Type: Inline - RelativeJump 0x3D94DEAE-->00000000 [guard32.dll]
[3380]orca.exe-->wininet.dll-->InternetConnectW, Type: Inline - RelativeJump 0x3D94F862-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2700]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2700]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2700]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2700]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2700]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2712]svchost.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2712]svchost.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2712]svchost.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2712]svchost.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[2712]svchost.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[2712]svchost.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2736]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2736]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2736]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2736]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2736]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2736]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2780]postgres.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2780]postgres.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2780]postgres.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2780]postgres.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2780]postgres.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2780]postgres.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[2856]mcrdsvc.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[2856]mcrdsvc.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[3168]searchindexer.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - RelativeJump 0x7C810E27-->00000000 [mssrch.dll]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - SEH 0x7C810E2C [unknown_code_page]
[3168]searchindexer.exe-->kernel32.dll-->WriteFile, Type: Inline - SEH 0x7C810E2D [unknown_code_page]
[3168]searchindexer.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[3168]searchindexer.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[3168]searchindexer.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[3168]searchindexer.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[332]ehSched.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[332]ehSched.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[332]ehSched.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[332]ehSched.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[332]ehSched.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateProcessAsUserA, Type: Inline - RelativeJump 0x77E10CE8-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateProcessAsUserW, Type: Inline - RelativeJump 0x77DEA8A9-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - RelativeJump 0x77E37211-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37216 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceA, Type: Inline - SEH 0x77E37217 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - RelativeJump 0x77E373A9-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AE [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->CreateServiceW, Type: Inline - SEH 0x77E373AF [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - RelativeJump 0x77DF4C66-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6B [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceA, Type: Inline - SEH 0x77DF4C6C [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - RelativeJump 0x77DE6FFD-->00000000 [guard32.dll]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7002 [unknown_code_page]
[3380]orca.exe-->advapi32.dll-->OpenServiceW, Type: Inline - SEH 0x77DE7003 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileA, Type: Inline - RelativeJump 0x7C8286EE-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExA, Type: Inline - RelativeJump 0x7C85F39C-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - RelativeJump 0x7C827B32-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B37 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileExW, Type: Inline - SEH 0x7C827B38 [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->CopyFileW, Type: Inline - RelativeJump 0x7C82F87B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateFileA, Type: Inline - RelativeJump 0x7C801A28-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateFileW, Type: Inline - RelativeJump 0x7C810800-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateProcessA, Type: Inline - RelativeJump 0x7C80236B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->CreateProcessW, Type: Inline - RelativeJump 0x7C802336-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->DeleteFileA, Type: Inline - RelativeJump 0x7C831EDD-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->DeleteFileW, Type: Inline - RelativeJump 0x7C831F63-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetModuleHandleA, Type: Inline - RelativeJump 0x7C80B741-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetModuleHandleW, Type: Inline - RelativeJump 0x7C80E4DD-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->GetProcAddress, Type: Inline - RelativeJump 0x7C80AE40-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryA, Type: Inline - RelativeJump 0x7C801D7B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExA, Type: Inline - RelativeJump 0x7C801D53-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - RelativeJump 0x7C801AF5-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFA [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->LoadLibraryExW, Type: Inline - SEH 0x7C801AFB [unknown_code_page]
[3380]orca.exe-->kernel32.dll-->LoadLibraryW, Type: Inline - RelativeJump 0x7C80AEEB-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->LoadModule, Type: Inline - RelativeJump 0x7C86261E-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileA, Type: Inline - RelativeJump 0x7C835EBF-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileExA, Type: Inline - RelativeJump 0x7C85E49B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileExW, Type: Inline - RelativeJump 0x7C83568B-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileW, Type: Inline - RelativeJump 0x7C821261-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileWithProgressA, Type: Inline - RelativeJump 0x7C835EDE-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->MoveFileWithProgressW, Type: Inline - RelativeJump 0x7C81F72E-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->OpenFile, Type: Inline - RelativeJump 0x7C821982-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->VirtualProtect, Type: Inline - RelativeJump 0x7C801AD4-->00000000 [guard32.dll]
[3380]orca.exe-->kernel32.dll-->WinExec, Type: Inline - RelativeJump 0x7C86250D-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrGetProcedureAddress, Type: Inline - RelativeJump 0x7C917EA8-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrLoadDll, Type: Inline - RelativeJump 0x7C9163C3-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->LdrUnloadDll, Type: Inline - RelativeJump 0x7C91738B-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtAllocateVirtualMemory, Type: Inline - RelativeJump 0x7C90CF6E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtClose, Type: Inline - RelativeJump 0x7C90CFEE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateFile, Type: Inline - RelativeJump 0x7C90D0AE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateProcess, Type: Inline - RelativeJump 0x7C90D14E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtCreateProcessEx, Type: Inline - RelativeJump 0x7C90D15E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtDeleteFile, Type: Inline - RelativeJump 0x7C90D23E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtFreeVirtualMemory, Type: Inline - RelativeJump 0x7C90D38E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtLoadDriver, Type: Inline - RelativeJump 0x7C90D46E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtOpenFile, Type: Inline - RelativeJump 0x7C90D59E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtProtectVirtualMemory, Type: Inline - RelativeJump 0x7C90D6EE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtSetInformationProcess, Type: Inline - RelativeJump 0x7C90DC9E-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtUnloadDriver, Type: Inline - RelativeJump 0x7C90DEBE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->NtWriteVirtualMemory, Type: Inline - RelativeJump 0x7C90DFAE-->00000000 [guard32.dll]
[3380]orca.exe-->ntdll.dll-->RtlAllocateHeap, Type: Inline - RelativeJump 0x7C9100C4-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteA, Type: Inline - RelativeJump 0x7CA411E0-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteEx, Type: Inline - RelativeJump 0x7CA40EB5-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteExW, Type: Inline - RelativeJump 0x7CA0996B-->00000000 [guard32.dll]
[3380]orca.exe-->shell32.dll-->ShellExecuteW, Type: Inline - RelativeJump 0x7CAB5D48-->00000000 [guard32.dll]
[3380]orca.exe-->user32.dll-->EndTask, Type: Inline - RelativeJump 0x7E45A0A5-->00000000 [guard32.dll]
[3380]orca.exe-->wininet.dll-->InternetConnectA, Type: Inline - RelativeJump 0x3D94DEAE-->00000000 [guard32.dll]
[3380]orca.exe-->wininet.dll-->InternetConnectW, Type: Inline - RelativeJump 0x3D94F862-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketA, Type: Inline - RelativeJump 0x71AB8B6A-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - RelativeJump 0x71AB404E-->00000000 [guard32.dll]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4053 [unknown_code_page]
[3380]orca.exe-->ws2_32.dll-->WSASocketW, Type: Inline - SEH 0x71AB4054 [unknown_code_page]