Vba32 AntiRootKit Log

Computer: INYOSTAR
OS: Microsoft Windows Vista Home Premium Edition Service Pack 2 (build 6002), loaded in normal mode
AntiRootKit version 3.12.5.2 build 168
AntiVirus checking is OFF
Sign checking is ON
Vba32 Defender is ON
AntiRootKit driver is working in ordinary mode
Log generation started: 19-03-2011 18:12:41

Content

Kernel modules

Don't display trusted items
Don't display user-mode images
Don't display unloaded modules

BaseEntry PointSizeDriverObjectPathState
0x776800000x127000
C:\Windows\System32\ntdll.dll
Signed User-mode image
0x804030000x804030000x7000
C:\Windows\system32\kdcom.dll
Signed
0x8040A0000x8040A0000x11000
C:\Windows\system32\PSHED.dll
Signed
0x8041B0000x8041B0000x8000
C:\Windows\system32\BOOTVID.dll
Signed
0x804230000x8045E0050x41000\Driver\CLFS [0x846F5450]
C:\Windows\system32\CLFS.SYS
Signed
0x804640000x804640000xE0000
C:\Windows\system32\CI.dll
Signed
0x805440000x805B50050x7C000\Driver\Wdf01000 [0x846EEE70]
C:\Windows\system32\drivers\Wdf01000.sys
Signed
0x805C00000x805CA0050xD000
C:\Windows\system32\drivers\WDFLDR.SYS
Signed
0x805CD0000x805F20350x2A000
C:\Windows\system32\DRIVERS\ks.sys
Signed
0x806000000x806017C50xD000\Driver\umbus [0x854FDF38]
C:\Windows\system32\DRIVERS\umbus.sys
Signed
0x8060D0000x8064A4900x46000\Driver\ACPI [0x846EE6F8]
C:\Windows\system32\drivers\acpi.sys
Signed
0x806530000x806590100x9000
C:\Windows\system32\drivers\WMILIB.SYS
Signed
0x8065C0000x8065D0700x8000\Driver\msisadrv [0x847148B8]
C:\Windows\system32\drivers\msisadrv.sys
Signed
0x806640000x80685CEB0x27000\Driver\pci [0x83DA2CA8]
C:\Windows\system32\drivers\pci.sys
Signed
0x8068B0000x8069722D0xF000\Driver\partmgr [0x846FAB08]
C:\Windows\System32\drivers\partmgr.sys
Signed
0x8069A0000x8069BDD30x3000\Driver\Compbatt [0x84773F38]
C:\Windows\system32\DRIVERS\compbatt.sys
Signed
0x8069D0000x806A30050xA000
C:\Windows\system32\DRIVERS\BATTC.SYS
Signed
0x806A70000x806B339B0xF000\Driver\volmgr [0x84714268]
C:\Windows\system32\drivers\volmgr.sys
Signed
0x806B60000x806F966E0x4A000\Driver\volmgrx [0x84715B28]
C:\Windows\System32\drivers\volmgrx.sys
Signed
0x807000000x807040050x7000\Driver\pciide [0x847157D8]
C:\Windows\system32\drivers\pciide.sys
Signed
0x807070000x807120100xE000
C:\Windows\system32\drivers\PCIIDEX.SYS
Signed
0x807150000x807222550x10000\Driver\MountMgr [0x847156E0]
C:\Windows\System32\drivers\mountmgr.sys
Signed
0x807250000x8072A0050x8000\Driver\atapi [0x847153F0]
C:\Windows\system32\drivers\atapi.sys
Signed
0x8072D0000x807470100x1E000
C:\Windows\system32\drivers\ataport.SYS
Signed
0x8074B0000x807769A70x32000\FileSystem\FltMgr [0x839A6DD8]
C:\Windows\system32\drivers\fltmgr.sys
Signed
0x8077D0000x807894C80x10000\FileSystem\FileInfo [0x846F4458]
C:\Windows\system32\drivers\fileinfo.sys
Signed
0x8078D0000x807F82A50x71000\Driver\KSecDD [0x846F6C58]
C:\Windows\System32\Drivers\ksecdd.sys
Signed
0x81C1B0000x81D074B00x3B9000\FileSystem\RAW [0x846D1990]
C:\Windows\system32\ntkrnlpa.exe ( ntoskrnl.exe )
Signed
0x81C1B0000x81D074B00x3B9000\Driver\WMIxWDM [0x839688D0]
C:\Windows\system32\ntkrnlpa.exe ( ntoskrnl.exe )
Signed
0x81C1B0000x81D074B00x3B9000\Driver\PnpManager [0x839A4A50]
C:\Windows\system32\ntkrnlpa.exe ( ntoskrnl.exe )
Signed
0x81FD40000x81FD40000x33000\Driver\ACPI_HAL [0x839561C8]
C:\Windows\system32\hal.dll
Signed
0x822000000x82206CD20xE000\Driver\circlass [0x85500118]
C:\Windows\system32\DRIVERS\circlass.sys
Signed
0x8220F0000x823101ED0x10B000\Driver\NDIS [0x846F7D50]
C:\Windows\system32\drivers\ndis.sys
Signed
0x8231A0000x823420320x2B000
C:\Windows\system32\drivers\msrpc.sys
Signed
0x823450000x8237B1120x3B000
C:\Windows\system32\drivers\NETIO.SYS
Signed
0x823800000x823BD0050x41000
C:\Windows\system32\DRIVERS\storport.sys
Signed
0x823C10000x823D30050x15000\Driver\RasSstp [0x8550E608]
C:\Windows\system32\DRIVERS\rassstp.sys
Signed
0x823D60000x823E32720x10000\Driver\TermDD [0x855003C8]
C:\Windows\system32\DRIVERS\termdd.sys
Signed
0x823E60000x823E9D900x1A000\Driver\VBoxNetFlt [0x85506BB0]
C:\Windows\system32\DRIVERS\VBoxNetFlt.sys
Signed
0x872010000x872DD1B90xE8000\Driver\Tcpip [0x846F7728]
C:\Windows\System32\drivers\tcpip.sys
Signed
0x872E90000x873010050x1B000
C:\Windows\System32\drivers\fwpkclnt.sys
Signed
0x873040000x8732100F0x21000
C:\Windows\system32\drivers\CLASSPNP.SYS
Signed
0x873250000x8732B0650x9000\Driver\crcdisk [0x84E9E478]
C:\Windows\system32\drivers\crcdisk.sys
Signed
0x8732E0000xD000
C:\Windows\System32\Drivers\crashdmp.sys
Signed Unloaded module ( 18:09:14 19.03.2011 )
0x8733B0000xB000dump_ataport.sysFile doesn't exist Unloaded module ( 18:09:14 19.03.2011 )
0x873460000x8000dump_atapi.sysFile doesn't exist Unloaded module ( 18:09:14 19.03.2011 )
0x8734E0000x873560050xB000\Driver\tunnel [0x8545BB08]
C:\Windows\system32\DRIVERS\tunnel.sys
Signed
0x873590000x8735E05E0x8000\Driver\FwLnk [0x85470D30]
C:\Windows\system32\DRIVERS\FwLnk.sys
Signed
0x873610000x873629780x10000\Driver\AmdK8 [0x8549C570]
C:\Windows\system32\DRIVERS\amdk8.sys
Signed
0x873710000x873AA0050x3E000
C:\Windows\system32\DRIVERS\USBPORT.SYS
Signed
0x873AF0000x873C40050x18000\Driver\cdrom [0x854798F8]
C:\Windows\system32\DRIVERS\cdrom.sys
Signed
0x873C70000x873E45D80x23000\Driver\NdisWan [0x85532240]
C:\Windows\system32\DRIVERS\ndiswan.sys
Signed
0x873EA0000x873FB0050x14000\Driver\PptpMiniport [0x8547D030]
C:\Windows\system32\DRIVERS\raspptp.sys
Signed
0x874050000x874F8B750x110000\FileSystem\Ntfs [0x84865F38]
C:\Windows\System32\Drivers\Ntfs.sys
Signed
0x875150000x875436400x39000\Driver\volsnap [0x84805B10]
C:\Windows\system32\drivers\volsnap.sys
Signed
0x8754E0000x875515050x5000\Driver\TVALZ [0x847FB6D8]
C:\Windows\system32\DRIVERS\TVALZ_O.SYS
Signed
0x875530000x8759A0050x4B000\Driver\tos_sps32 [0x848B6268]
C:\Windows\system32\DRIVERS\tos_sps32.sys
Signed
0x8759E0000x875A33310x8000\Driver\spldr [0x847E2688]
C:\Windows\System32\Drivers\spldr.sys
Signed
0x875A60000x875AA0000x7000\Driver\pssnap [0x8480C680]
C:\Windows\system32\DRIVERS\pssnap.sys
Signed
0x875AD0000x875B90480xF000\FileSystem\Mup [0x847F4648]
C:\Windows\System32\Drivers\mup.sys
Signed
0x875BC0000x875DE1CE0x27000\Driver\Ecache [0x847FE8D8]
C:\Windows\System32\drivers\ecache.sys
Signed
0x875E30000x875F0BBC0x11000\Driver\disk [0x849228A8]
C:\Windows\system32\drivers\disk.sys
Signed
0x875F40000x875F904D0x8000\Driver\AtiPcie [0x847ABAD8]
C:\Windows\system32\DRIVERS\AtiPcie.sys
Signed
0x8A6000000x8AD160050x728000\Driver\atikmdag [0x8545A198]
C:\Windows\system32\DRIVERS\atikmdag.sys
Signed
0x8AD280000x8ADBD0050x9F000\Driver\DXGKrnl [0x85469298]
C:\Windows\System32\drivers\dxgkrnl.sys
Signed
0x8ADC70000x8ADD00050xC000
C:\Windows\System32\drivers\watchdog.sys
Signed
0x8ADD30000x8ADDA0050xA000\Driver\usbohci [0x8547E330]
C:\Windows\system32\DRIVERS\usbohci.sys
Signed
0x8ADDD0000x8ADE90050xF000\Driver\usbehci [0x8547EF38]
C:\Windows\system32\DRIVERS\usbehci.sys
Signed
0x8ADEC0000x8ADEF4B50x4000\Driver\tdcmdpst [0x8545DD30]
C:\Windows\system32\DRIVERS\tdcmdpst.sys
Signed
0x8ADF00000x8ADFC07E0xF000\Driver\RasPppoe [0x85531CC8]
C:\Windows\system32\DRIVERS\raspppoe.sys
Signed
0x8B0000000x8B000B5D0x2000\Driver\swenum [0x85506D30]
C:\Windows\system32\DRIVERS\swenum.sys
Signed
0x8B0020000x8B00912A0xA000\Driver\mssmbios [0x855012E8]
C:\Windows\system32\DRIVERS\mssmbios.sys
Signed
0x8B00E0000x8B017A670x8D000\Driver\HDAudBus [0x854CCBE0]
C:\Windows\system32\DRIVERS\HDAudBus.sys
Signed
0x8B09B0000x8B0A90550x13000\Driver\i8042prt [0x85463E90]
C:\Windows\system32\DRIVERS\i8042prt.sys
Signed
0x8B0AE0000x8B0B58020xB000\Driver\kbdclass [0x8553DF38]
C:\Windows\system32\DRIVERS\kbdclass.sys
Signed
0x8B0B90000x8B0DEEB40x2D000\Driver\SynTP [0x854C2A08]
C:\Windows\system32\DRIVERS\SynTP.sys
Signed
0x8B0E60000x8B0E71050x2000
C:\Windows\system32\DRIVERS\USBD.SYS
Signed
0x8B0E80000x8B0EF7DD0xB000\Driver\mouclass [0x8546DD08]
C:\Windows\system32\DRIVERS\mouclass.sys
Signed
0x8B0F30000x8B0FE8850x10000\Driver\ohci1394 [0x8562BF38]
C:\Windows\system32\DRIVERS\ohci1394.sys
Signed
0x8B1030000x8B10ED050xE000
C:\Windows\system32\DRIVERS\1394BUS.SYS
Signed
0x8B1110000x8B1263930x1A000\Driver\sdbus [0x8548BB28]
C:\Windows\system32\DRIVERS\sdbus.sys
Signed
0x8B12B0000x8B1370750xF000\Driver\rimmptsk [0x854772C0]
C:\Windows\system32\DRIVERS\rimmptsk.sys
Signed
0x8B13A0000x8B14B0750x14000\Driver\rimsptsk [0x854F4490]
C:\Windows\system32\DRIVERS\rimsptsk.sys
Signed
0x8B14E0000x8B19C0050x51000\Driver\rismxdp [0x854774D8]
C:\Windows\system32\DRIVERS\rixdptsk.sys
Signed
0x8B19F0000x8B1A19BC0x4000\Driver\CmBatt [0x85477030]
C:\Windows\system32\DRIVERS\CmBatt.sys
Signed
0x8B1A30000x8B1CE0050x2F000\Driver\iScsiPrt [0x85533EB8]
C:\Windows\system32\DRIVERS\msiscsi.sys
Signed
0x8B1D20000x8B1DA0050xB000
C:\Windows\system32\DRIVERS\TDI.SYS
Signed
0x8B1DD0000x8B1F10050x17000\Driver\Rasl2tp [0x855336B0]
C:\Windows\system32\DRIVERS\rasl2tp.sys
Signed
0x8B1F40000x8B1FC1B50xB000\Driver\NdisTapi [0x8547D338]
C:\Windows\system32\DRIVERS\ndistapi.sys
Signed
0x8B4070000x8B4380050x35000\Driver\usbhub [0x85503F38]
C:\Windows\system32\DRIVERS\usbhub.sys
Signed
0x8B43C0000x8B44A2930x11000\Driver\NDProxy [0x856A3400]
C:\Windows\System32\Drivers\NDProxy.SYS
Signed
0x8B44D0000x8B558A400x11C000\Driver\AgereSoftModem [0x856FE318]
C:\Windows\system32\DRIVERS\AGRSM.sys
Signed
0x8B5690000x8B57319B0xD000\Driver\Modem [0x856F5478]
C:\Windows\system32\drivers\modem.sys
Signed
0x8B5760000x8B59E0050x2D000
C:\Windows\system32\drivers\portcls.sys
Signed
0x8B5A30000x8B5C403E0x25000
C:\Windows\system32\drivers\drmk.sys
Signed
0x8B5C80000x8B5DBF050x17000\Driver\SBRE [0x85763478]
C:\Windows\system32\drivers\SBREdrv.sys
Signed
0x8B5DF0000x8B5E4D850x7000
C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Signed
0x8B5E60000x8B5EF0C20xC000\Driver\VgaSave [0x8576D3A0]
C:\Windows\System32\drivers\vga.sys
Signed
0x8B6000000x9000
C:\Windows\System32\Drivers\kbdhid.sys
Signed Unloaded module ( 18:09:12 19.03.2011 )
0x8B6000000x8B6070380xA000\Driver\nsiproxy [0x857F7478]
C:\Windows\system32\drivers\nsiproxy.sys
Signed
0x8B60B0000x8B7D90450x1D9000\Driver\IntcAzAudAddService [0x8571B318]
C:\Windows\system32\drivers\RTKVHDA.sys
Signed
0x8B7E40000x8B7EA2560x9000\FileSystem\Fs_Rec [0x85744478]
C:\Windows\System32\Drivers\Fs_Rec.SYS
Signed
0x8B7ED0000x8B7F10830x7000\Driver\Null [0x85748410]
C:\Windows\System32\Drivers\Null.SYS
Signed
0x8B7F40000x8B7F80050x7000\Driver\Beep [0x8573E478]
C:\Windows\System32\Drivers\Beep.SYS
Signed
0x8BA000000x8BA1BE0A0x21000
C:\Windows\System32\drivers\VIDEOPRT.SYS
Signed
0x8BA210000x8BA260050x8000\Driver\RDPCDD [0x85772318]
C:\Windows\System32\DRIVERS\RDPCDD.sys
Signed
0x8BA290000x8BA2E0050x8000\Driver\RDPENCDD [0x8576C478]
C:\Windows\system32\drivers\rdpencdd.sys
Signed
0x8BA310000x8BA3929A0xB000\FileSystem\Msfs [0x85775478]
C:\Windows\System32\Drivers\Msfs.SYS
Signed
0x8BA3C0000x8BA4758A0xE000\FileSystem\Npfs [0x858045C0]
C:\Windows\System32\Drivers\Npfs.SYS
Signed
0x8BA4A0000x8BA502B80x9000\Driver\RasAcd [0x8576E3D0]
C:\Windows\System32\DRIVERS\rasacd.sys
Signed
0x8BA530000x8BA660050x16000\Driver\tdx [0x8577D478]
C:\Windows\system32\DRIVERS\tdx.sys
Signed
0x8BA690000x8BA794FB0x14000\Driver\Smb [0x8578F410]
C:\Windows\system32\DRIVERS\smb.sys
Signed
0x8BA7D0000x8BAB85040x48000\Driver\AFD [0x85780478]
C:\Windows\system32\drivers\afd.sys
Signed
0x8BAC50000x8BAC94050x6000\Driver\CSN5PDTS82 [0x8578F318]
C:\Windows\System32\Drivers\CSN5PDTS82.sys
Signed
0x8BACB0000x8BAF70B10x32000\Driver\netbt [0x856D34D0]
C:\Windows\System32\DRIVERS\netbt.sys
Signed
0x8BAFD0000x8BB0C0050x16000\Driver\PSched [0x856D7108]
C:\Windows\system32\DRIVERS\pacer.sys
Signed
0x8BB130000x8BB174500x5C000\Driver\pwipf6 [0x857E85B8]
C:\Windows\system32\DRIVERS\pwipf6.sys
Signed
0x8BB6F0000x8BB7A2780xE000\FileSystem\NetBIOS [0x857E7980]
C:\Windows\system32\DRIVERS\netbios.sys
Signed
0x8BB7D0000x8BB8C4E10x13000\Driver\Wanarpv6 [0x857DF968]
C:\Windows\system32\DRIVERS\wanarp.sys
Signed
0x8BB900000x8BB90BE00x9000\Driver\VBoxUSBMon [0x859AB890]
C:\Windows\system32\DRIVERS\VBoxUSBMon.sys
Signed
0x8BB990000x8BB99C900x22000\Driver\VBoxDrv [0x858EF4C8]
C:\Windows\system32\DRIVERS\VBoxDrv.sys
Signed
0x8BBBB0000x8BBF11CE0x3C000\FileSystem\rdbss [0x859EBF38]
C:\Windows\system32\DRIVERS\rdbss.sys
Signed
0x8BE090000x8BE1C3E10x17000\FileSystem\DfsC [0x857A6DE8]
C:\Windows\System32\Drivers\dfsc.sys
Signed
0x8BE200000x8BE3F2140x23000\Driver\AntiLog32 [0x8585B640]
C:\Program Files\AntiLogger\AntiLog32.sys
Signed
0x8BE430000x8BE570050x17000\Driver\usbccgp [0x85884EC0]
C:\Windows\system32\DRIVERS\usbccgp.sys
Signed
0x8BE5A0000x8BE600050x9000\Driver\HidUsb [0x8588CF38]
C:\Windows\system32\DRIVERS\hidusb.sys
Signed
0x8BE630000x8BE700050x10000
C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Signed
0x8BE730000x8BE796040x9000\Driver\kbdhid [0x85870F38]
C:\Windows\system32\DRIVERS\kbdhid.sys
Signed
0x8BE7C0000x8BE8127D0x8000\Driver\mouhid [0x85882808]
C:\Windows\system32\DRIVERS\mouhid.sys
Signed
0x8BE840000x8BE922C20x46000\Driver\RTL8187B [0x858C2668]
C:\Windows\system32\DRIVERS\RTL8187B.sys
Signed
0x8BECA0000x8BED40050xD000
C:\Windows\System32\Drivers\crashdmp.sys
Signed
0x8BED70000x8BEDF0050xB000C:\Windows\System32\Drivers\dump_dumpata.sys ( dump_ataport.sys )File doesn't exist
0x8BEE20000x8BEE70050x8000C:\Windows\System32\Drivers\dump_atapi.sysFile doesn't exist
0x8BEEA0000x8BEF10050xA000
C:\Windows\System32\drivers\Dxapi.sys
Signed
0x8BEF40000x8BEF6B020xF000\Driver\monitor [0x85D8B5C0]
C:\Windows\system32\DRIVERS\monitor.sys
Signed
0x8BF030000x8BF162CD0x1B000\FileSystem\luafv [0x85EBA518]
C:\Windows\system32\drivers\luafv.sys
Signed
0x8BF1E0000x8BF2CB3E0x11000\FileSystem\a2acc [0x85ECEF38]
C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys
Signed
0x8BF2F0000x8000
C:\Windows\System32\Drivers\drmkaud.sys
Signed Unloaded module ( 18:09:57 19.03.2011 )
0x8BF370000x8BFE01EB0xB0000
C:\Windows\system32\drivers\spsys.sys
Signed
0x912800000x9146A0EC0x202000\Driver\Win32k [0x847147C0]
C:\Windows\System32\win32k.sys
Signed
0x914A00000x914A21450x9000
C:\Windows\System32\TSDDD.dll
Signed
0x914C00000x914C7B840xE000
C:\Windows\System32\cdd.dll
Signed
0x948030000x9481D8440x21000\Driver\SbieDrv [0x85FDC650]
C:\Program Files\Sandboxie\SbieDrv.sys
Signed
0x948240000x948309E70x10000\Driver\lltdio [0x85FEA868]
C:\Windows\system32\DRIVERS\lltdio.sys
Signed
0x948340000x948593CE0x2A000\Driver\NativeWifiP [0x85FEA030]
C:\Windows\system32\DRIVERS\nwifi.sys
Signed
0x9485E0000x948651D40xA000\Driver\Ndisuio [0x85DF2BB8]
C:\Windows\system32\DRIVERS\ndisuio.sys
Signed
0x948680000x9487741B0x13000\Driver\rspndr [0x85FFBAF8]
C:\Windows\system32\DRIVERS\rspndr.sys
Signed
0x9487B0000x948CD4CB0x6B000\Driver\HTTP [0x85A4AF38]
C:\Windows\system32\drivers\HTTP.sys
Signed
0x948E60000x948F70050x15000\Driver\mpsdrv [0x8605A118]
C:\Windows\System32\drivers\mpsdrv.sys
Signed
0x948FB0000x18000
C:\Windows\System32\Drivers\parport.sys
Signed Unloaded module ( 18:09:35 19.03.2011 )
0x949130000x949281E50x19000\FileSystem\bowser [0x847B1900]
C:\Windows\system32\DRIVERS\bowser.sys
Signed
0x9492C0000x949460050x1F000\FileSystem\mrxsmb [0x860B4E90]
C:\Windows\system32\DRIVERS\mrxsmb.sys
Signed
0x9494B0000x9497E0050x39000\FileSystem\mrxsmb10 [0x860D8BE8]
C:\Windows\system32\DRIVERS\mrxsmb10.sys
Signed
0x949840000x949980050x18000\FileSystem\mrxsmb20 [0x860CE448]
C:\Windows\system32\DRIVERS\mrxsmb20.sys
Signed
0x95C0F0000x95CE81830xDE000\Driver\PEAUTH [0x860E3640]
C:\Windows\system32\drivers\peauth.sys
Signed
0x95CED0000x95CF405F0xA000\Driver\secdrv [0x86102610]
C:\Windows\System32\Drivers\secdrv.SYS
Signed
0x95CF70000x95D0F0400x1D000\FileSystem\srvnet [0x86105C80]
C:\Windows\System32\DRIVERS\srvnet.sys
Signed
0x95D140000x95D1D0050xC000\Driver\tcpipreg [0x8609D590]
C:\Windows\System32\drivers\tcpipreg.sys
Signed
0x95D200000x95D420050x27000\FileSystem\srv2 [0x86144F00]
C:\Windows\System32\DRIVERS\srv2.sys
Signed
0x95D470000x95D8B0050x4C000\FileSystem\srv [0x86144030]
C:\Windows\System32\DRIVERS\srv.sys
Signed
0x95D930000x95DA50400x16000\FileSystem\cdfs [0x86389570]
C:\Windows\system32\DRIVERS\cdfs.sys
Signed
0x95DA90000x95DC30060x1D000\Driver\3qyhufha [0x840F1E50]
C:\Windows\system32\drivers\3qyhufha.sys
VBA32 Signed
Total:
Up

Kernel-Mode Hooks

Don't display trusted items

ModuleTypeNumberNameBase ValueCurrent ValueDriverState
C:\Windows\system32\ntkrnlpa.exeCode Modification (3 bytes)-PAGE +0x10A9B20x81D54000-
C:\Windows\system32\ntkrnlpa.exeCode Modification (4 bytes)-PAGE +0x1043DC0x81D54000-
C:\Windows\system32\ntkrnlpa.exeCode Modification (4 bytes)-PAGE +0x0D2E550x81D54000-
C:\Windows\system32\ntkrnlpa.exeCode Modification (6 bytes)-.text +0x02A3280x81C1C000-
C:\Windows\system32\ntkrnlpa.exeSSDT383NtCreateUserProcess0x81DE4B820x8BB1FBF0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT358NtWriteVirtualMemory0x81E284D90x8BE232AAC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeCode Modification - Relative Jump-NtTraceEvent +0x00000x81C463260x934B9C00
C:\Windows\system32\ntkrnlpa.exeSSDT335NtTerminateThread0x81E370CF0x8BB1F560C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT334NtTerminateProcess0x81E0BD5D0x8BE23BAEC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT324NtSetValueKey0x81DF90220x8BE23EC2C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT317NtSetSystemInformation0x81E01B160x8BE237A0C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT289NtSetContextThread0x81EAD2530x8BE23378C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT286NtSecureConnectPort0x81DE86800x8BE2441CC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT282NtResumeThread0x81E366E50x8BB1FB40C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeCode Modification - Relative Jump-NtRequestWaitReplyPort +0x00020x81E5E9AE0x934B9D40
C:\Windows\system32\ntkrnlpa.exeCode Modification - Relative Jump-NtRequestPort +0x00020x81E26E520x934B9CA0
C:\Windows\system32\ntkrnlpa.exeSSDT255NtQueueApcThread0x81DCC8130x8BE238BEC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT210NtProtectVirtualMemory0x81E34E7D0x8BE24484C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT201NtOpenThread0x81E3709A0x8BE239E0C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT197NtOpenSection0x81E2C2190x8BE23A96C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT194NtOpenProcess0x81E3BB480x8BE23930C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT189NtOpenKey0x81E232430x8BE23FC2C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT186NtOpenFile0x81E20F990x8BE242EEC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT177NtMapViewOfSection0x81E2B4460x8BE233E6C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT165NtLoadDriver0x81D86DF00x8BE23644C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT127NtDeviceIoControlFile0x81E62EE60x8BE24562C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT126NtDeleteValueKey0x81DC8C740x8BE23CC8C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT123NtDeleteKey0x81DCD6D30x8BE23DF6C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT116NtDebugActiveProcess0x81E7F6EA0x8BB1DDB0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT78NtCreateThread0x81EAC5800x8BE2380EC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT77NtCreateSymbolicLinkObject0x81DDB3060x8BE244C4C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT71NtCreatePort0x81DA0A400x8BB20390C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT64NtCreateKey0x81E09D5D0x8BB1E2F0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT60NtCreateFile0x81E5CD590x8BE24008C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\system32\ntkrnlpa.exeSSDT54NtConnectPort0x81DE8AA70x8BB20070C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\system32\ntkrnlpa.exeCode Modification - Relative Jump-NtAlpcSendWaitReceivePort +0x00020x81E583D90x934B9DE0
C:\Windows\system32\ntkrnlpa.exeSSDT12NtAdjustPrivilegesToken0x81E0B26F0x8BB1E650C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x128FB00x91281000-
C:\Windows\System32\win32k.sysCode Modification - Ret-.text +0x11BCF70x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x0F90FB0x91281000-
C:\Windows\System32\win32k.sysCode Modification (5 bytes)-.text +0x0D55410x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x0BE0300x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x0BCDA60x91281000-
C:\Windows\System32\win32k.sysCode Modification (3 bytes)-.text +0x0A5AFE0x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x09C6D00x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x0988D20x91281000-
C:\Windows\System32\win32k.sysCode Modification (6 bytes)-.text +0x091F070x91281000-
C:\Windows\System32\win32k.sysCode Modification (5 bytes)-.text +0x0517E70x91281000-
C:\Windows\System32\win32k.sysCode Modification (6 bytes)-.text +0x04EC920x91281000-
C:\Windows\System32\win32k.sysCode Modification (4 bytes)-.text +0x0411DF0x91281000-
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSystemParametersInfo +0x00000x91326AFC0x934B9A20
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserShowWindow +0x00020x912D27E40x934B9700
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSetWinEventHook +0x00020x912C21DC0x934B9980
C:\Windows\System32\win32k.sysShadow SSDT576NtUserSetWinEventHook0x912C21DC0x8BB1CEB0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSetWindowsHookEx +0x00000x91312F050x934B98E0
C:\Windows\System32\win32k.sysShadow SSDT573NtUserSetWindowsHookEx0x91312F050x8BB1CDD0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSetSystemCursor +0x00020x913A9FAD0x934B9B60
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSetSysColors +0x00000x9135653F0x934B9AC0
C:\Windows\System32\win32k.sysShadow SSDT532NtUserSetClipboardViewer0x913749390x8BE22F06C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserSendInput +0x00000x9139CCF50x934B97A0
C:\Windows\System32\win32k.sysShadow SSDT525NtUserSendInput0x9139CCF50x8BB1D880C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT513NtUserRegisterRawInputDevices0x9129FC700x8BB1D580C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserPostThreadMessage +0x00020x9131D6CD0x934B9520
C:\Windows\System32\win32k.sysShadow SSDT498NtUserPostThreadMessage0x9131D6CD0x8BB1D300C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserPostMessage +0x00020x9133F02D0x934B9480
C:\Windows\System32\win32k.sysShadow SSDT497NtUserPostMessage0x9133F02D0x8BB1D180C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserMessageCall +0x00020x9133DDA30x934B93E0
C:\Windows\System32\win32k.sysShadow SSDT479NtUserMessageCall0x9133DDA30x8BB1CFF0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT430NtUserGetKeyState0x91340E5A0x8BB1D6E0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT401NtUserGetClassInfoEx0x9131DBA80x8BE231ECC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT397NtUserGetAsyncKeyState0x912AFDAA0x8BB1D7B0C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserDestroyWindow +0x00020x913198CF0x934B9660
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserCallHwndParamLock +0x00020x912CFC8F0x934B95C0
C:\Windows\System32\win32k.sysCode Modification - Relative Jump-NtUserBlockInput +0x00020x9137A0F80x934B9840
C:\Windows\System32\win32k.sysShadow SSDT317NtUserAttachThreadInput0x91396C3C0x8BB1D470C:\Windows\system32\DRIVERS\pwipf6.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT307NtGdiTransparentBlt0x912B9B7B0x8BE22D8CC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT301NtGdiStretchBlt0x91344EEB0x8BE22BDEC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT245NtGdiPlgBlt0x9137DC270x8BE22D0EC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT241NtGdiOpenDCW0x913105C20x8BE22AB8C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT235NtGdiMaskBlt0x912B8DB00x8BE22C76C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT198NtGdiGetPixel0x912C30F10x8BE22E88C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT124NtGdiDeleteObjectApp0x9134B5830x8BE22A9EC:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT13NtGdiBitBlt0x9134EC590x8BE22B46C:\Program Files\AntiLogger\AntiLog32.sysSigned
C:\Windows\System32\win32k.sysShadow SSDT7NtGdiAlphaBlend0x91323C340x8BE22E0AC:\Program Files\AntiLogger\AntiLog32.sysSigned
Total:
Up

Kernel-Mode Notificators

Don't display trusted items

TypeCurrent AddressDriverAdditionState
Registry Callback0x8BE2138EC:\Program Files\AntiLogger\AntiLog32.sysSigned
LoadImage0x8633D3D8Vba32 AntiRootKit HandlerVBA32
LoadImage0x948157D8C:\Program Files\Sandboxie\SbieDrv.sysSigned
LoadImage0x8BE21312C:\Program Files\AntiLogger\AntiLog32.sysSigned
LoadImage0x81E3982BC:\Windows\system32\ntkrnlpa.exeSigned
CreateThread0x8BB1AB80C:\Windows\system32\DRIVERS\pwipf6.sysSigned
CreateProcess0x95CD3C4AC:\Windows\system32\drivers\peauth.sysSigned
CreateProcess0x9481569AC:\Program Files\Sandboxie\SbieDrv.sysSigned
CreateProcess0x8BE21208C:\Program Files\AntiLogger\AntiLog32.sysSigned
CreateProcess0x8BB1B270C:\Windows\system32\DRIVERS\pwipf6.sysSigned
CreateProcess0x80535B47C:\Windows\system32\CI.dllSigned
CreateProcess0x872553EEC:\Windows\System32\drivers\tcpip.sysSigned
CreateProcess0x807C5F8EC:\Windows\System32\Drivers\ksecdd.sysSigned
CreateProcess0x81C442DDC:\Windows\system32\ntkrnlpa.exeSigned
SeFileSystem0x8BF11B5AC:\Windows\system32\drivers\luafv.sysSigned
Shutdown0x81C439D2C:\Windows\system32\ntkrnlpa.exeDeviceObject = 0x839686B8Signed
Shutdown0x81EAFFE4C:\Windows\system32\ntkrnlpa.exeDeviceObject = 0x846D1B98Signed
Shutdown0x8071663AC:\Windows\System32\drivers\mountmgr.sysDeviceObject = 0x847154E8Signed
Shutdown0x805785E6C:\Windows\system32\drivers\Wdf01000.sysDeviceObject = 0x8553CAE8Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x85488028Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x85464028Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x8547A028Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x85555028Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x85588028Signed
Shutdown0x8B42955EC:\Windows\system32\DRIVERS\usbhub.sysDeviceObject = 0x855F8028Signed
Shutdown0x8BA0910DC:\Windows\System32\drivers\VIDEOPRT.SYSDeviceObject = 0x857C7040Signed
Shutdown0x8BA0910DC:\Windows\System32\drivers\VIDEOPRT.SYSDeviceObject = 0x857C5840Signed
Shutdown0x8BA0910DC:\Windows\System32\drivers\VIDEOPRT.SYSDeviceObject = 0x857C7C48Signed
LastChanceShutdown0x806A8B84C:\Windows\system32\drivers\volmgr.sysDeviceObject = 0x84715C20Signed
LastChanceShutdown0x8B5CCADCC:\Windows\system32\drivers\SBREdrv.sysDeviceObject = 0x857423F0Signed
BugCheckReason0x8072F0C2C:\Windows\system32\drivers\ataport.SYSCallbackRecord = 0x8073B0C0Signed
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x83D7A264Signed
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x8546AFB4Signed
BugCheckReason0x8AD3A0B8C:\Windows\System32\drivers\dxgkrnl.sysCallbackRecord = 0x8AD472E4Signed
BugCheckReason0x8739A4CCC:\Windows\system32\DRIVERS\USBPORT.SYSCallbackRecord = 0x8546E5B8Signed
BugCheckReason0x8739A526C:\Windows\system32\DRIVERS\USBPORT.SYSCallbackRecord = 0x8549CED0Signed
BugCheckReason0x8739A46FC:\Windows\system32\DRIVERS\USBPORT.SYSCallbackRecord = 0x85469070Signed
BugCheckReason0x8B0724FFC:\Windows\system32\DRIVERS\HDAudBus.sysCallbackRecord = 0x8547E7CCSigned
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x854C089CSigned
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x855007F4Signed
BugCheckReason0x8B003E06C:\Windows\system32\DRIVERS\mssmbios.sysCallbackRecord = 0x8B0074E0Signed
BugCheckReason0x8B003E4EC:\Windows\system32\DRIVERS\mssmbios.sysCallbackRecord = 0x8B0074A0Signed
BugCheckReason0x8B003E9EC:\Windows\system32\DRIVERS\mssmbios.sysCallbackRecord = 0x8B007480Signed
BugCheckReason0x8B003EE6C:\Windows\system32\DRIVERS\mssmbios.sysCallbackRecord = 0x8B0074C0Signed
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x854FFFB4Signed
BugCheckReason0x8B4295B0C:\Windows\system32\DRIVERS\usbhub.sysCallbackRecord = 0x85529730Signed
BugCheckReason0x8B429605C:\Windows\system32\DRIVERS\usbhub.sysCallbackRecord = 0x855288D8Signed
BugCheckReason0x8BA03FB7C:\Windows\System32\drivers\VIDEOPRT.SYSCallbackRecord = 0x8BA07100Signed
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x8587AD7CSigned
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x859BAA94Signed
BugCheckReason0x80580A31C:\Windows\system32\drivers\Wdf01000.sysCallbackRecord = 0x860E4DACSigned
BugCheck0x81FE1F60C:\Windows\system32\hal.dllCallbackRecord = 0x81FEEE60Signed
BugCheck0x82240D2FC:\Windows\system32\drivers\ndis.sysCallbackRecord = 0x8547172CSigned
BugCheck0x82240D2FC:\Windows\system32\drivers\ndis.sysCallbackRecord = 0x8547072CSigned
BugCheck0x82240D2FC:\Windows\system32\drivers\ndis.sysCallbackRecord = 0x8549372CSigned
Total:
Up

Driver Input/Output Handler's Hooks (IRP & FastIo)

Don't display trusted items

Driver ObjectHandler NameCurrent AddressDriverState
\Driver\monitorIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\monitorIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\msisadrvIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\circlassIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\PEAUTHIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\AmdK8IRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\atikmdagIRP_MJ_PNP0x8AD6705DC:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_SYSTEM_CONTROL0x8AD87948C:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_POWER0x8ADA9826C:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_INTERNAL_DEVICE_CONTROL0x8AD663DEC:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_DEVICE_CONTROL0x8AD6C5B8C:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_CLOSE0x8AD5FE16C:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\atikmdagIRP_MJ_CREATE0x8AD5FD47C:\Windows\System32\drivers\dxgkrnl.sysSigned
\Driver\umbusIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\umbusIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_PNP0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SET_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_QUERY_QUOTA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_DEVICE_CHANGE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SYSTEM_CONTROL0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_POWER0x8057880DC:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SET_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_QUERY_SECURITY0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_CREATE_MAILSLOT0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_CLEANUP0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_LOCK_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SHUTDOWN0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_INTERNAL_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_DEVICE_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_FILE_SYSTEM_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_DIRECTORY_CONTROL0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SET_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_QUERY_VOLUME_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_FLUSH_BUFFERS0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SET_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_QUERY_EA0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_SET_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_QUERY_INFORMATION0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_WRITE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_READ0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_CLOSE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_CREATE_NAMED_PIPE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
\Driver\SynTPIRP_MJ_CREATE0x805785E6C:\Windows\system32\drivers\Wdf01000.sysSigned
Total:
Up

Processes

Don't display trusted items
Don't display zombie processes

Column View Options

Short NamePIDParent PIDThreadsModulesFull PathState
System40109156Anomaly detected
svchost.exe328624225
C:\Windows\System32\svchost.exe
Signed
svchost.exe448624848
C:\Windows\System32\svchost.exe
Signed
smss.exe456442
C:\Windows\System32\smss.exe
Signed
svchost.exe480624224
C:\Windows\System32\svchost.exe
Signed
svchost.exe492624644
C:\Windows\System32\svchost.exe
Signed
ReflectService.exe504624233
C:\Program Files\Macrium\Reflect\ReflectService.exe
Signed
SnareCore.exe512624734
C:\Program Files\Snare\SnareCore.exe
csrss.exe5245121033
C:\Windows\System32\csrss.exe
Signed
wininit.exe580512528
C:\Windows\System32\wininit.exe
Signed
csrss.exe5925721135
C:\Windows\System32\csrss.exe
Signed
services.exe6245802734
C:\Windows\System32\services.exe
Signed
lsass.exe6405801968
C:\Windows\System32\lsass.exe
Signed
lsm.exe6525801433
C:\Windows\System32\lsm.exe
Signed
winlogon.exe680572832
C:\Windows\System32\winlogon.exe
Signed
svchost.exe8366241342
C:\Windows\System32\svchost.exe
Signed
a2service.exe8806242159
C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Signed
svchost.exe9886241836
C:\Windows\System32\svchost.exe
Signed
svchost.exe102462413055
C:\Windows\System32\svchost.exe
Signed
TNaviSrv.exe1088624321
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
Ati2evxx.exe1124624629
C:\Windows\System32\Ati2evxx.exe
Signed
svchost.exe11446244382
C:\Windows\System32\svchost.exe
Signed Anomaly detected
svchost.exe116862459102
C:\Windows\System32\svchost.exe
Signed
svchost.exe1216624111122
C:\Windows\System32\svchost.exe
Signed
audiodg.exe130411441544
C:\Windows\System32\audiodg.exe
Signed
dllhost.exe13408365
C:\Windows\System32\dllhost.exe
Zombie process Signed
TODDSrv.exe1356624424
C:\Windows\System32\TODDSrv.exe
SLsvc.exe1364624524
C:\Windows\System32\SLsvc.exe
Signed
svchost.exe14286244176
C:\Windows\System32\svchost.exe
Signed
TosBtSrv.exe1492624325
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
Signed
Ati2evxx.exe15201124936
C:\Windows\System32\Ati2evxx.exe
Signed
SbieSvc.exe1528624636
C:\Program Files\Sandboxie\SbieSvc.exe
Signed
pfsvc.exe16406242540
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
Signed
spoolsv.exe17686242094
C:\Windows\System32\spoolsv.exe
Signed
svchost.exe17966244059
C:\Windows\System32\svchost.exe
Signed
ULCDRSvr.exe185662426
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
agrsmsvc.exe1940624218
C:\Windows\System32\agrsmsvc.exe
Signed
svchost.exe19566242672
C:\Windows\System32\svchost.exe
Signed
svchost.exe1968624410
C:\Windows\System32\svchost.exe
Signed
PresentationFontCache.exe1980624634
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Signed
taskeng.exe222812162425
C:\Windows\System32\taskeng.exe
Signed
dllhost.exe24048365
C:\Windows\System32\dllhost.exe
Zombie process Signed
taskeng.exe246012161768
C:\Windows\System32\taskeng.exe
Signed
dwm.exe25081168734
C:\Windows\System32\dwm.exe
Signed
explorer.exe2612242073153
C:\Windows\explorer.exe
Signed
RtHDVCpl.exe276026121049
C:\Windows\RtHDVCpl.exe
Signed
SynTPStart.exe27802612425
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
Signed
AntiLogger.exe282426121676
C:\Program Files\AntiLogger\AntiLogger.exe
Signed
PFGUI.exe2832261220123
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
Signed
jusched.exe28402612325
C:\Program Files\Common Files\Java\Java Update\jusched.exe
Signed
TOSCDSPD.exe28562612218
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
SbieCtrl.exe28722612534
C:\Program Files\Sandboxie\SbieCtrl.exe
Signed
rundll32.exe290022282
C:\Windows\System32\rundll32.exe
Zombie process Signed
rundll32.exe296022282
C:\Windows\System32\rundll32.exe
Zombie process Signed
MOM.exe300427882061
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
Anomaly detected
consent.exe316012165
C:\Windows\System32\consent.exe
Zombie process Signed
AntiLogger.exe321628241
C:\Program Files\AntiLogger\AntiLogger.exe
Zombie process Signed
dllhost.exe32248365
C:\Windows\System32\dllhost.exe
Zombie process Signed
SynTPEnh.exe32642780631
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Signed
CCC.exe3276300473260
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
Anomaly detected
SynToshiba.exe33163264223
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
Signed
SynTPEnh.exe348827801
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Zombie process Signed
WmiPrvSE.exe35328363
C:\Windows\System32\wbem\WmiPrvSE.exe
Zombie process Signed
WmiPrvSE.exe35928366
C:\Windows\System32\wbem\WmiPrvSE.exe
Zombie process Signed
WmiApSrv.exe36526245
C:\Windows\System32\wbem\WmiApSrv.exe
Zombie process Signed
dllhost.exe43048365
C:\Windows\System32\dllhost.exe
Zombie process Signed
consent.exe4364121611
C:\Windows\System32\consent.exe
Zombie process Signed
dllhost.exe44848365
C:\Windows\System32\dllhost.exe
Zombie process Signed
dllhost.exe45128365
C:\Windows\System32\dllhost.exe
Zombie process Signed
Vba32arkit.exe455226122075
C:\Users\Punymicro\Desktop\backup\vba32arkit_beta\Vba32arkit.exe
ADS:Yes Signed
ctfmon.exe456445522
C:\Windows\System32\ctfmon.exe
Zombie process Signed
ctfmon.exe46444552224
C:\Windows\System32\ctfmon.exe
Signed
rundll32.exe470422282
C:\Windows\System32\rundll32.exe
Zombie process Signed
WmiPrvSE.exe4828836741
C:\Windows\System32\wbem\WmiPrvSE.exe
Signed
rundll32.exe490422282
C:\Windows\System32\rundll32.exe
Zombie process Signed
WmiPrvSE.exe54568364
C:\Windows\System32\wbem\WmiPrvSE.exe
Zombie process Signed
WMIADAP.exe554812163
C:\Windows\System32\wbem\WMIADAP.exe
Zombie process Signed
WmiPrvSE.exe56488363
C:\Windows\System32\wbem\WmiPrvSE.exe
Zombie process Signed
Total:
Up

Threads

Don't display trusted items

Column View Options

EthreadTIDStateService TableTEBStart AddressStart ModuleHidden From DebuggerInformation
System ( PID : 4 )
0x84FA1D78216Terminated0x81D52B000x875C8F68ecache.sysNoTerminated
0x840012285140Waiting0x81D52B000x95DAA0063qyhufha.sysNo
0x840F50204292Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83EF0BA01608Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83ED14C04056Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x85D949D83996Waiting0x81D52B000x81E5EB62ntkrnlpa.exeNo
0x85A5AD783496Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x8622F4602448Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x8607D2A01892Waiting0x81D52B000x948F1BE0mpsdrv.sysNo
0x860495801764Waiting0x81D52B000x948A2409HTTP.sysNo
0x860498281760Waiting0x81D52B000x948A2005HTTP.sysNo
0x86049AD01756Waiting0x81D52B000x948A2005HTTP.sysNo
0x86049D781752Waiting0x81D52B000x948A2005HTTP.sysNo
0x860490201748Waiting0x81D52B000x948A2005HTTP.sysNo
0x860482801744Waiting0x81D52B000x948A2005HTTP.sysNo
0x860485281740Waiting0x81D52B000x948A2005HTTP.sysNo
0x860487D01736Waiting0x81D52B000x948A2005HTTP.sysNo
0x86048A781732Waiting0x81D52B000x948A2005HTTP.sysNo
0x85FC86D81480Waiting0x81D52B000x8BF97115spsys.sysNo
0x85D8C020876Waiting0x81D52B000x8BF0C5C2luafv.sysNo
0x85D8F658696Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x85E6EB00604Waiting0x81D52B000x82324411msrpc.sysNo
0x85BEDCD0548Waiting0x81D52B000x8AD9356Fdxgkrnl.sysNo
0x85A4BD78544Waiting0x81D52B000x8A6306D6atikmdag.sysNo
0x85BECD78540Waiting0x81D52B000x8A703EE8atikmdag.sysNo
0x85BE3D78536Waiting0x81D52B000x8ACEF9C8atikmdag.sysNo
0x8586FD78452Waiting0x81D52B000x81DDC228ntkrnlpa.exeNo
0x85850D78444Waiting0x81D52B000x8BBC0EC6rdbss.sysNo
0x857D32D0440Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857D3578436Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857D3820432Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857F7560428Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857FAD78424Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857F6178420Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x859E3970416Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857F4D78412Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x857F3D78408Waiting0x81D52B000x8BBE9B32rdbss.sysNo
0x856D9088392Waiting0x81D52B000x8BA4BF6Crasacd.sysNo
0x857A58D0388Waiting0x81D52B000x8B5CCF8ESBREdrv.sysNo
0x857B16D0384Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x8562D4D0380Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x8562D778376Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x856D5378372Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x856D5620368Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x856DB548364Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x8581F778360Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x8562DD78356Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x855EDD78352Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x855ED470348Waiting0x81D52B000x8B60E3F0RTKVHDA.sysNo
0x856CEAD0344Waiting0x81D52B000x8B464280AGRSM.sysNo
0x856CED78340Waiting0x81D52B000x8B4616C0AGRSM.sysNo
0x856C1020312Waiting0x81D52B000x873EB5C1raspptp.sysNo
0x8564C020288Waiting0x81D52B000x8B1550ACrixdptsk.sysNo
0x85631658284Waiting0x81D52B000x8B1546EArixdptsk.sysNo
0x85631020280Waiting0x81D52B000x8B14108Arimsptsk.sysNo
0x855FB478276Waiting0x81D52B000x8B14067Crimsptsk.sysNo
0x85657020272Waiting0x81D52B000x8B132220rimmptsk.sysNo
0x85637AB8268Waiting0x81D52B000x8B131D48rimmptsk.sysNo
0x854FB470260Waiting0x81D52B000x823E81C0VBoxNetFlt.sysNo
0x85533020248Waiting0x81D52B000x8B1548E6rixdptsk.sysNo
0x85477A28244Waiting0x81D52B000x8B14086Arimsptsk.sysNo
0x85477CD0240Waiting0x81D52B000x8B131862rimmptsk.sysNo
0x854693E0236Waiting0x81D52B000x8AD93F5Fdxgkrnl.sysNo
0x85478A58232Waiting0x81D52B000x8ADC84E2watchdog.sysNo
0x85478D78228Waiting0x81D52B000x8AD967E8dxgkrnl.sysNo
0x84815CF0220Waiting0x81D52B000x87412385Ntfs.sysNo
0x847FB7C0208Waiting0x81D52B000x875C7F3Eecache.sysNo
0x84800708204Waiting0x81D52B000x875C95CEecache.sysNo
0x846EE020200Waiting0x81D52B000x8061CCA0acpi.sysNo
0x846F36A0180Waiting0x81D52B000x82210C1Endis.sysNo
0x846F7810176Waiting0x81D52B000x822E8692ndis.sysNo
0x846EF020168Waiting0x81D52B000x8062250Eacpi.sysNo
0x846CEAB8164Waiting0x81D52B000x81E0837Entkrnlpa.exeNo
0x846BDD78160Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83E7CD78152Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83E37670148Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83E37D78144Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83DB2370140Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x83DB2918136Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x8396A6B0132Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x8396AD18128Waiting0x81D52B000x81E476F9ntkrnlpa.exeNo
0x839A0D78120Waiting0x81D52B000x81C1C4BCntkrnlpa.exeNo
0x839A0020116Waiting0x81D52B000x81C1C4BCntkrnlpa.exeNo
0x839A2020112Waiting0x81D52B000x81C50900ntkrnlpa.exeNo
0x839A3540108Waiting0x81D52B000x81C50249ntkrnlpa.exeNo
0x839A37E8104Waiting0x81D52B000x81C4FAFEntkrnlpa.exeNo
0x839A3CD0100Waiting0x81D52B000x81C8CD5Dntkrnlpa.exeNo
0x839A302096Unknown0x81D52B000x81CA8155ntkrnlpa.exeNo
0x839A458092Waiting0x81D52B000x81C78CCBntkrnlpa.exeNo
0x8399C65088Waiting0x81D52B000x81C4AABCntkrnlpa.exeNo
0x8399C8F884Waiting0x81D52B000x81C4AABCntkrnlpa.exeNo
0x8399AAD080Waiting0x81D52B000x81E28880ntkrnlpa.exeNo
0x8399AD7876Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x8399A02072Waiting0x81D52B000x8399A214NoNo module corresponds thread's start address
0x839992D868Waiting0x81D52B000x92DB71C0NoNo module corresponds thread's start address
0x8399958064Waiting0x81D52B000x8CD9D628NoNo module corresponds thread's start address
0x8399982860Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x83999AD056Waiting0x81D52B000x83999CC4NoNo module corresponds thread's start address
0x83999D7852Waiting0x81D52B000x94570C00NoNo module corresponds thread's start address
0x8399902048Waiting0x81D52B000x83999214NoNo module corresponds thread's start address
0x839982D844Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x8399858040Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x8399882836Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x83998AD032Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x83998D7828Waiting0x81D52B000x81CC0D25ntkrnlpa.exeNo
0x8395817824Waiting0x81D52B000x81C203AFntkrnlpa.exeNo
0x8395842020Waiting0x81D52B000x81C203AFntkrnlpa.exeNo
0x839586C816Waiting0x81D52B000x81C1D4C2ntkrnlpa.exeNo
0x839736688Unknown0x81D52B000x87C72128NoNo module corresponds thread's start address
svchost.exe ( PID : 328 )
0x860CF030332Waiting0x81D52B400x7FFDD0000x7623F36Fadvapi32.dllNo
0x860D4D78316Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
svchost.exe ( PID : 448 )
0x844FA7506004Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8616C0302156Waiting0x81D52B000x7FFD70000x726898FEwiaservc.dllNo
0x8615E9802152Waiting0x81D52B000x7FFD80000x71D3269Efundisc.dllNo
0x8616B3482148Waiting0x81D52B400x7FFD90000x71D31D3Bfundisc.dllNo
0x86133C601636Waiting0x81D52B000x7FFDB0000x71D32875fundisc.dllNo
0x8611AC481632Waiting0x81D52B000x7FFDC0000x77860148rpcrt4.dllNo
0x8610F408844Waiting0x81D52B400x7FFDE0000x7623F36Fadvapi32.dllNo
0x86044030820Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
smss.exe ( PID : 456 )
0x85E6D030568Waiting0x81D52B000x7FFDB0000x47DEB564smss.exeNo
0x85BCDD78520Waiting0x81D52B000x7FFDC0000x47DEA0BAsmss.exeNo
0x85BDAD78508Waiting0x81D52B000x7FFDD0000x47DEB564smss.exeNo
0x857CDD78460Waiting0x81D52B000x7FFDE0000x47DED9A2smss.exeNo
svchost.exe ( PID : 480 )
0x860F0210484Waiting0x81D52B400x7FFDE0000x7623F36Fadvapi32.dllNo
0x860F3A60500Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
svchost.exe ( PID : 492 )
0x86130D081292Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E0AC784028Waiting0x81D52B000x7FFD80000x77860148rpcrt4.dllNo
0x861042C0572Waiting0x81D52B000x7FFDB0000x776C2808ntdll.dllNo
0x861034D0576Waiting0x81D52B000x7FFDC0000x776C2D40ntdll.dllNo
0x860F27A0488Waiting0x81D52B400x7FFDD0000x7623F36Fadvapi32.dllNo
0x860F14D8496Waiting0x81D52B000x7FFDE0000x00E42083svchost.exeNo
ReflectService.exe ( PID : 504 )
0x860F58D8528Waiting0x81D52B400x7FFDE0000x7623F36Fadvapi32.dllNo
0x860F2428532Waiting0x81D52B400x7FFDF0000x00416196ReflectService.exeNo
SnareCore.exe ( PID : 512 )
0x861318781444Waiting0x81D52B000x7FFD80000x77860148rpcrt4.dllNo
0x86117D781296Waiting0x81D52B000x7FFD90000x0041F36BSnareCore.exeNo
0x861167401252Waiting0x81D52B000x7FFDA0000x0041F36BSnareCore.exeNo
0x8610E960644Waiting0x81D52B000x7FFDB0000x776C2808ntdll.dllNo
0x8610C350824Waiting0x81D52B000x7FFDD0000x0041F36BSnareCore.exeNo
0x86106AC8712Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x86105D78596Waiting0x81D52B400x7FFDF0000x00420C77SnareCore.exeNo
csrss.exe ( PID : 524 )
0x860974881988Waiting0x81D52B400x7FFD50000x75E55633csrsrv.dllNo
0x85BAED78660Waiting0x81D52B400x7FFD60000x75DD2D2Awinsrv.dllNo
0x85DBA990648Waiting0x81D52B400x7FFD70000x75DD9DD3winsrv.dllNo
0x85CEBAC0612Waiting0x81D52B400x7FFD80000x75DD9DD3winsrv.dllNo
0x85CEBD78608Waiting0x81D52B400x7FFDA0000x75DD9DD3winsrv.dllNo
0x859B8B48588Waiting0x81D52B400x7FFDF0000x75E55633csrsrv.dllNo
0x85B57D78564Waiting0x81D52B000x7FFDB0000x75E54526csrsrv.dllNo
0x85E6B030560Waiting0x81D52B400x7FFDC0000x75E55633csrsrv.dllNo
0x85BB0D78556Waiting0x81D52B000x7FFDD0000x75DD9DEFwinsrv.dllNo
0x85BB2D78552Waiting0x81D52B400x7FFDE0000x75DD8C87winsrv.dllNo
wininit.exe ( PID : 580 )
0x864E60303852Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E2C6B8740Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85D8CD78636Waiting0x81D52B000x7FFDB0000x776C2808ntdll.dllNo
0x85E6BD78600Waiting0x81D52B000x7FFDE0000x77860148rpcrt4.dllNo
0x85A2DD78584Waiting0x81D52B400x7FFDF0000x003E634Bwininit.exeNo
csrss.exe ( PID : 592 )
0x862E64702888Waiting0x81D52B400x7FFD50000x75E55633csrsrv.dllNo
0x862D60302880Waiting0x81D52B400x7FFD60000x75E55633csrsrv.dllNo
0x862C0D782756Waiting0x81D52B400x7FFD70000x75E55633csrsrv.dllNo
0x85BFDD78828Waiting0x81D52B400x7FFD80000x75DD9DD3winsrv.dllNo
0x85DCA258704Waiting0x81D52B400x7FFD90000x75DD9DD3winsrv.dllNo
0x85DC46B0688Waiting0x81D52B400x7FFDE0000x75E55633csrsrv.dllNo
0x85DB8A78676Waiting0x81D52B000x7FFDA0000x75E54526csrsrv.dllNo
0x85DC1030672Waiting0x81D52B400x7FFDB0000x75E55633csrsrv.dllNo
0x85D90768668Waiting0x81D52B000x7FFDC0000x75DD9DEFwinsrv.dllNo
0x85DB8D78664Waiting0x81D52B400x7FFDD0000x75DD8C87winsrv.dllNo
0x85DFF968632Waiting0x81D52B000x914C30A6cdd.dllNo
services.exe ( PID : 624 )
0x841ED0305808Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844980305744Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84210A605592Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840979E05440Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8401D6385264Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8633CD785136Terminated0x81D52B000x00E9AE8Aservices.exeNoTerminated
0x85FC80304980Terminated0x81D52B000x00E9AE8Aservices.exeNoTerminated
0x85981C884964Terminated0x81D52B000x00E9AE8Aservices.exeNoTerminated
0x861108084952Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85FBF0304948Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863C50304820Terminated0x81D52B000x00E9AE8Aservices.exeNoTerminated
0x84146AC84656Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841434604632Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84060C904148Terminated0x81D52B000x75D61EDEncobjapi.dllNoTerminated
0x83FBF0303132Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F7F4382940Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85EC1D78800Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85EB8AC0796Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85F3FD78788Terminated0x81D52B000x75D64035ncobjapi.dllNoTerminated
0x85EF1030780Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85D31CC0628Terminated0x81D52B400x00EA388Dservices.exeNoTerminated
0x844F5B106088Waiting0x81D52B000x7FFDD0000x77860148rpcrt4.dllNo
0x840D07A05948Waiting0x81D52B000x7FFDF0000x77860148rpcrt4.dllNo
0x85ED7D784176Waiting0x81D52B000x7FFDA0000x75D620A0ncobjapi.dllNo
0x8405E4984172Waiting0x81D52B000x7FFDB0000x75D64986ncobjapi.dllNo
0x85EB3D78872Waiting0x81D52B000x7FFD50000x776C2D40ntdll.dllNo
0x85EF1590776Waiting0x81D52B000x7FFDE0000x776C2808ntdll.dllNo
lsass.exe ( PID : 640 )
0x844B30305960Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844BA0C05912Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8449F8B85780Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844A4D785776Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841854D84480Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8403EAC04164Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FF18583192Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EC3030812Terminated0x81D52B000x752C3E91gpapi.dllNoTerminated
0x85E2B7A0724Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8460F6A06076Waiting0x81D52B000x7FFDF0000x77860148rpcrt4.dllNo
0x85EB4690768Waiting0x81D52B000x7FFAE0000x75AFAC06lsasrv.dllNo
0x85EB4D78760Waiting0x81D52B000x7FFD30000x75AFAC06lsasrv.dllNo
0x85EB3078752Waiting0x81D52B000x7FFD50000x75AFAC06lsasrv.dllNo
0x85EB1D78748Waiting0x81D52B000x7FFD70000x77860148rpcrt4.dllNo
0x85E2C030728Waiting0x81D52B000x7FFD90000x75ACE61Dlsasrv.dllNo
0x85E2B030720Waiting0x81D52B000x7FFDB0000x776C2D40ntdll.dllNo
0x85B7ED78716Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x85DCC030708Waiting0x81D52B000x7FFDD0000x75AE5E74lsasrv.dllNo
0x85DF5030700Waiting0x81D52B000x7FFDE0000x756C3391EMET.dllNo
lsm.exe ( PID : 652 )
0x844B06285984Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840170304724Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8406FD784212Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F3C2901672Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E650301020Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863A53585192Waiting0x81D52B000x7FFD70000x77860148rpcrt4.dllNo
0x85F340301072Waiting0x81D52B400x7FFD50000x776C2D40ntdll.dllNo
0x85F310301068Waiting0x81D52B000x7FFD60000x776C2D40ntdll.dllNo
0x85F323601060Waiting0x81D52B000x7FFD80000x776C2D40ntdll.dllNo
0x85F020301048Waiting0x81D52B000x7FFD90000x776C2D40ntdll.dllNo
0x85F02D781044Waiting0x81D52B000x7FFDA0000x776C2808ntdll.dllNo
0x85EF44F81040Waiting0x81D52B000x7FFDB0000x776C2D40ntdll.dllNo
0x85EF47B01036Waiting0x81D52B000x7FFDC0000x776C2D40ntdll.dllNo
0x85D8D2C8656Waiting0x81D52B400x7FFDE0000x00F43C46lsm.exeNo
winlogon.exe ( PID : 680 )
0x84169D784416Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x84168B704412Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85ED1BA84048Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85D98C704004Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x855410304000Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85F017481100Waiting0x81D52B000x7FFDB0000x776C2808ntdll.dllNo
0x85D8F910692Waiting0x81D52B000x7FFDE0000x77860148rpcrt4.dllNo
0x85DC1D78684Waiting0x81D52B400x7FFDF0000x00525EAEwinlogon.exeNo
svchost.exe ( PID : 836 )
0x84444D005640Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x841914F05340Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8647CAA84804Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84165A584404Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FF4D783196Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85EC8D10856Terminated0x81D52B000x752C3E91gpapi.dllNoTerminated
0x85EC8030848Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F595F85452Waiting0x81D52B000x7FFDD0000x77860148rpcrt4.dllNo
0x85EEA700956Waiting0x81D52B000x7FFD50000x776C2D40ntdll.dllNo
0x85EEE8E0936Waiting0x81D52B000x7FFD60000x776C2D40ntdll.dllNo
0x85EC8448864Waiting0x81D52B400x7FFD90000x751587EAumpnpmgr.dllNo
0x85EC04B8852Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x85A4FD78840Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
a2service.exe ( PID : 880 )
0x85F26030984Waiting0x81D52B000x7FFA70000x74F26430a2acc.dllNo
0x85F230F8980Waiting0x81D52B000x7FFA80000x74F26430a2acc.dllNo
0x85F22B70976Waiting0x81D52B000x7FFA90000x74F26430a2acc.dllNo
0x85F142D0972Waiting0x81D52B000x7FFAA0000x74F26430a2acc.dllNo
0x85F10030968Waiting0x81D52B000x7FFAB0000x74F26430a2acc.dllNo
0x85F0D238960Waiting0x81D52B000x7FFAC0000x74F26430a2acc.dllNo
0x85EEA9B8952Waiting0x81D52B000x7FFAD0000x74F26430a2acc.dllNo
0x85EE9C38948Waiting0x81D52B000x7FFAE0000x74F26430a2acc.dllNo
0x85EEB338944Waiting0x81D52B000x7FFAF0000x74F26430a2acc.dllNo
0x85EEE628940Waiting0x81D52B000x7FFD30000x74F26430a2acc.dllNo
0x85ECB030924Waiting0x81D52B400x7FFD40000x0040673Ca2service.exeNo
0x85EDAAC0920Waiting0x81D52B000x7FFD50000x0040673Ca2service.exeNo
0x85EDAD78916Waiting0x81D52B000x7FFD60000x0040673Ca2service.exeNo
0x85EDA030912Waiting0x81D52B000x7FFD70000x0040673Ca2service.exeNo
0x85ECC640908Waiting0x81D52B000x7FFD80000x0040673Ca2service.exeNo
0x85ECC8F8904Waiting0x81D52B000x7FFD90000x0040673Ca2service.exeNo
0x85EBE818900Waiting0x81D52B000x7FFDB0000x0040673Ca2service.exeNo
0x85ECCBB0896Waiting0x81D52B400x7FFDC0000x0040673Ca2service.exeNo
0x85EBEAD0892Waiting0x81D52B000x7FFDD0000x7623F36Fadvapi32.dllNo
0x85A6AD78888Waiting0x81D52B000x7FFDE0000x0040673Ca2service.exeNo
0x85EBDD78884Waiting0x81D52B400x7FFDF0000x00621768a2service.exeNo
svchost.exe ( PID : 988 )
0x83F497785480Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FFFD785468Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8418A0305240Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86307B005220Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8623B4004868Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84071D504836Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840650304768Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x841650304528Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F92D783048Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F3D0302224Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85BC6D781016Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85F3B8401008Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844F3D005992Waiting0x81D52B000x7FFD90000x77860148rpcrt4.dllNo
0x846249105980Waiting0x81D52B000x7FFDA0000x74CC8AA4rpcss.dllNo
0x85F397081004Waiting0x81D52B000x7FFDB0000x776C2808ntdll.dllNo
0x85EDB5201000Waiting0x81D52B000x7FFDC0000x776C2D40ntdll.dllNo
0x85F3AC60996Waiting0x81D52B400x7FFDD0000x7623F36Fadvapi32.dllNo
0x85F3A740992Waiting0x81D52B000x7FFDE0000x00E42083svchost.exeNo
svchost.exe ( PID : 1024 )
0x844E9A005900Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x844E1BF05876Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844E16A85872Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844DA1F05868Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x844DE6305860Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844610305708Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x841E69805700Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x844530305668Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844542085664Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x844520305660Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8421F7885644Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8414FD785580Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FD64485516Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841BA9805512Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FA83A85508Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8406A0305504Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FB57685500Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862A6C485404Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x840BCC685384Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83ED27F05380Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x84034A485376Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F9BAC05372Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85E9C3685368Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840884605364Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862FA0305208Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EF18985204Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8630CCC05072Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86135C605032Terminated0x81D52B400x76E55795ole32.dllNoTerminated
0x8615E0305028Terminated0x81D52B000x76E55795ole32.dllNoTerminated
0x860665A05004Terminated0x81D52B400x744E1BE2wscapi.dllNoTerminated
0x863DB0304932Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x862AFD784916Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x86234D784864Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x854777804744Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F80B904740Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841431A84736Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x841740304732Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83EC32E84664Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x841950304620Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x840D55704612Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x8414A0304608Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x8423B9D04604Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x8405B8804600Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x840DA0304596Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8414E6B04360Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840F57684356Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8413BAC04352Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x84156B504348Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840680704192Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x840257F82976Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FFBA002372Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FED6C02384Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x863060302396Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FD9D782380Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FD2CB83304Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83FA7D781080Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F77D782804Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F76D782808Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F77468620Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F748302720Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F76A782716Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F74C102708Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F670302656Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F69D782692Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F71D782688Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F71AC02664Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F6E8B82440Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x8621DCD02648Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F70B382584Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F680302544Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE57E82596Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F619802572Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F610302568Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F60D782576Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F61D782580Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F5C5882536Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F5AA102452Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F42A482392Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x855448002124Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F50D102116Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F46A801552Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F56CC82076Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F42D782288Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F557B0744Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EF2D78832Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EF1D782256Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EF3BB02260Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EF10302268Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE6D782276Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F4AD102264Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F3B7601676Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F3B0301720Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F3A0301272Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F362D81584Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83F35D781404Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83ECD0301336Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE82301092Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85EA3630736Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE8960964Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EEFD78732Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85EA3D781512Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x855400301468Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85DF8A781612Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EED1901624Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EEC8F02112Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85D94610516Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EEB0302052Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE9A78468Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x85EA63782084Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE65C0404Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83EE20304084Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83ED05384076Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83ED10304072Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83ECEA384068Terminated0x81D52B000x74C5CEC1MpClient.dllNoTerminated
0x83ECECF04064Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x857A9D784052Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8631FD783876Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85FB15B01328Terminated0x81D52B000x74C302E1MpSvc.dllNoTerminated
0x85F467281120Terminated0x81D52B400x74C078D3MpSvc.dllNoTerminated
0x85F29B381112Terminated0x81D52B000x752C3E91gpapi.dllNoTerminated
0x844DF8785864Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x85FAE5D04060Waiting0x81D52B000x7FFAF0000x743E882AMpRtPlug.dllNo
0x85FA49681320Waiting0x81D52B000x7FFD40000x743E2458MpRtPlug.dllNo
0x85FB2AC01316Waiting0x81D52B000x7FFD50000x74C0EC84MpSvc.dllNo
0x85FB2D781312Waiting0x81D52B000x7FFD60000x74C0FDCFMpSvc.dllNo
0x85F594A01180Waiting0x81D52B000x7FFD70000x74C19EE7MpSvc.dllNo
0x85F6D0301176Waiting0x81D52B000x7FFD80000x74C0CADFMpSvc.dllNo
0x85F2B5581116Waiting0x81D52B000x7FFDA0000x776C2D40ntdll.dllNo
0x85F417E81108Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x85EF25581028Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
TNaviSrv.exe ( PID : 1088 )
0x858175A81496Waiting0x81D52B000x7FFDC0000x00401120TNaviSrv.exeNo
0x861164581332Waiting0x81D52B000x7FFDD0000x7623F36Fadvapi32.dllNo
0x8611B7D81032Waiting0x81D52B400x7FFDE0000x00402577TNaviSrv.exeNo
Ati2evxx.exe ( PID : 1124 )
0x8606C0301816Terminated0x81D52B000x0040C580Ati2evxx.exeNoTerminated
0x860447A01824Waiting0x81D52B000x7FFDA0000x0040AC40Ati2evxx.exeNo
0x8606EBF01820Waiting0x81D52B400x7FFDC0000x0040AC70Ati2evxx.exeNo
0x85F18D781140Waiting0x81D52B400x7FFDD0000x00427E20Ati2evxx.exeNo
0x85F39C301136Waiting0x81D52B400x7FFDE0000x7623F36Fadvapi32.dllNo
0x85F445C01128Waiting0x81D52B400x7FFDF0000x00450CF9Ati2evxx.exeNo
svchost.exe ( PID : 1144 )
0x844E7D785952Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840860305920Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844EE9F85916Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844E00A85852Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x84481D785760Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840D70305740Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841D7D785572Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840CFA985532Terminated0x81D52B000x75840735crypt32.dllNoTerminated
0x83F8FB705496Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8414A9485492Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8419C7C85428Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FB50305416Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862363985184Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85FDFC785060Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86056AC04988Terminated0x81D52B000x75840735crypt32.dllNoTerminated
0x863E1D784972Terminated0x81D52B400x7623F36Fadvapi32.dllNoTerminated
0x862583604812Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8616B0304808Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85CE4A404800Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FF06184792Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FE6C204748Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x84196D784628Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841954304624Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840BFD784224Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840624D04184Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84033A902684Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85E0A7884020Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85F67B701224Terminated0x81D52B000x752C3E91gpapi.dllNoTerminated
0x85F560301164Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85F50C801152Terminated0x81D52B400x7623F36Fadvapi32.dllNoTerminated
0x85DFA4E86064Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x86071A385000Waiting0x81D52B000x7FFA50000x695B1DD7wscsvc.dllNo
0x8627AD784996Waiting0x81D52B000x7FFA60000x776C2D40ntdll.dllNo
0x86273AC84992Waiting0x81D52B000x7FFA70000x695B67DBwscsvc.dllNo
0x85FAB0301344Waiting0x81D52B400x7FFD30000x74501F72MMDevAPI.dllNo
0x85939D781300Waiting0x81D52B000x7FFDE0000x7447DBA1audiosrv.dllNo
0x85F73CB81236Waiting0x81D52B000x7FFD60000x745DFD09wevtsvc.dllNo
0x85F678B81232Waiting0x81D52B000x7FFD70000x745DFD09wevtsvc.dllNo
0x85F674A81228Waiting0x81D52B000x7FFD80000x745DFD09wevtsvc.dllNo
0x85F66D781212Waiting0x81D52B000x7FFDA0000x776C2808ntdll.dllNo
0x85F45AC01160Waiting0x81D52B400x7FFDC0000x745E30CCwevtsvc.dllNo
0x85F45D781156Waiting0x81D52B000x7FFDD0000x745E079Bwevtsvc.dllNo
0x85F539481148Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
svchost.exe ( PID : 1168 )
0x840430306080Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8445A0305964Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844E9D785940Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844CD5105904Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840C47605816Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840864D05800Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844B27805796Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x842363305720Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8444D3585704Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840A6A805524Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8408F6F05520Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840400305288Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F6CAC85256Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8400F3005252Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x861243F05224Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86392D785144Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8543C5705128Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FF31C84756Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840ADC504216Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840687804196Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85ED7AC04188Terminated0x81D52B000x71CC3CE9sysmain.dllNoTerminated
0x83EEA0301472Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EA6B784092Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83EE46904088Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x864547304012Terminated0x81D52B000x71CB4D2Fsysmain.dllNoTerminated
0x864665403992Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85430A501688Terminated0x81D52B000x7624D5ECadvapi32.dllNoTerminated
0x85926AC01288Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862196806100Waiting0x81D52B000x7FFD70000x77860148rpcrt4.dllNo
0x83F605786084Waiting0x81D52B000x7FFAD0000x776C2D40ntdll.dllNo
0x844EBD786052Waiting0x81D52B000x7FFA40000x776C2D40ntdll.dllNo
0x8445A7E06028Waiting0x81D52B000x7FFD40000x77860148rpcrt4.dllNo
0x84164AC04560Waiting0x81D52B000x7FFD80000x72C33B18pcasvc.dllNo
0x85FE48C02212Waiting0x81D52B000x7FF9B0000x72FE1267wdi.dllNo
0x8613E3702208Waiting0x81D52B000x7FF9C0000x72FE1267wdi.dllNo
0x85FCED782204Waiting0x81D52B000x7FF9D0000x72FE1267wdi.dllNo
0x85FDA6882200Waiting0x81D52B000x7FF9E0000x72FE1267wdi.dllNo
0x85FCBD782196Waiting0x81D52B000x7FF9F0000x72FE1267wdi.dllNo
0x85FCB5602192Waiting0x81D52B000x7FFA00000x72FE1267wdi.dllNo
0x85FCB8182188Waiting0x81D52B000x7FFA10000x72FE1267wdi.dllNo
0x85FE29182184Waiting0x81D52B000x7FFA20000x72FE1267wdi.dllNo
0x8607EB382180Waiting0x81D52B000x7FFA30000x72FE1267wdi.dllNo
0x8616FD782176Waiting0x81D52B000x7FFA50000x72FE1267wdi.dllNo
0x85FDECA82172Waiting0x81D52B000x7FFA60000x7623F36Fadvapi32.dllNo
0x861115D0928Waiting0x81D52B000x7FFA70000x7623F36Fadvapi32.dllNo
0x860F460812Waiting0x81D52B000x7FFA90000x72C5117Dhidserv.dllNo
0x860DCBB0400Waiting0x81D52B000x7FFA80000x72C51A7Fhidserv.dllNo
0x860DC030336Waiting0x81D52B400x7FFAA0000x72C51587hidserv.dllNo
0x860AFB38292Waiting0x81D52B000x7FFAB0000x7623F36Fadvapi32.dllNo
0x8609D7302004Waiting0x81D52B000x7FFAC0000x72BA1471emdmgmt.dllNo
0x86096D781976Waiting0x81D52B000x7FFDC0000x7623F36Fadvapi32.dllNo
0x86015A781696Waiting0x81D52B000x7FFAF0000x73325458wlgpclnt.dllNo
0x854304601692Waiting0x81D52B000x7FFD30000x77252670msvcrt.dllNo
0x85FE19601616Waiting0x81D52B000x7FFD50000x736CDB7AWUDFPlatform.dllNo
0x85FE60301592Waiting0x81D52B000x7FFD60000x73BD2C31uxsms.dllNo
0x85F797601276Waiting0x81D52B400x7FFDB0000x74501F72MMDevAPI.dllNo
0x85F6B2401256Waiting0x81D52B000x7FFDE0000x7447DBA1audiosrv.dllNo
0x85F6A8981248Waiting0x81D52B000x7FFDD0000x776C2808ntdll.dllNo
0x85F59B701172Waiting0x81D52B400x7FFDF0000x00E42083svchost.exeNo
svchost.exe ( PID : 1216 )
0x83FA44286020Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844F60305968Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8445BA785956Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844AF7805804Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841C69685788Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E623605772Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8449FD785752Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x8445DD785728Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844647885724Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8444C8785636Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x844447B05632Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x8413D7805584Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841D0D785540Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840EAD785528Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8418DB705448Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x84096AF85444Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x840BB4A85420Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FE12185408Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x84095D785316Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x8413C2105312Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x83F50A585308Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x83F420305304Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x8409FD785276Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F84D785272Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862E69805212Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86336D285200Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863516A05196Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x860460304984Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x863A67984940Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x863653504936Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x863078484876Terminated0x81D52B000x76E55795ole32.dllNoTerminated
0x863E08284824Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x860A82F84816Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x8408B0304788Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x83F4CD004784Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x83F99B604780Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8417C3304776Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840757384716Terminated0x81D52B000x72902F1Bssdpapi.dllNoTerminated
0x83EEA8984688Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x83F63D784668Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8403D4C04592Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841787E04548Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84139B004392Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84142BA84336Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x8413B0304324Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8405F6004180Terminated0x81D52B400x67CB4F52NCProv.dllNoTerminated
0x84038D784112Terminated0x81D52B400x7166B972wbemcomn.dllNoTerminated
0x840553484108Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x840556004104Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x84055AC04100Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x84055D781284Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x840550301560Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x855473383204Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x840543902788Terminated0x81D52B400x6ACA2ABBwbemcore.dllNoTerminated
0x8402E7782796Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x83EE2BE82964Terminated0x81D52B400x7166C0E0wbemcomn.dllNoTerminated
0x83FD5D783228Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x83FAD0301076Terminated0x81D52B000x7624D5ECadvapi32.dllNoTerminated
0x83F90AF81188Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F77AC02752Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F5D9682848Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83EC47A04036Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83EC30304032Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8644D8383688Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8639CD783516Terminated0x81D52B000x75D64035ncobjapi.dllNoTerminated
0x8639DA583512Terminated0x81D52B000x75D64035ncobjapi.dllNoTerminated
0x862182D02416Terminated0x81D52B000x73DF6D46gpsvc.dllNoTerminated
0x86217B702400Terminated0x81D52B400x73DF5CE2gpsvc.dllNoTerminated
0x860AF7D0320Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x85FBCD781400Terminated0x81D52B400x73DF5CE2gpsvc.dllNoTerminated
0x86028D781392Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x844BEA006096Waiting0x81D52B000x7FFDC0000x776C2D40ntdll.dllNo
0x844F2BA05976Waiting0x81D52B000x7FFD90000x776C2D40ntdll.dllNo
0x85FAEC885928Waiting0x81D52B000x7FFA20000x776C2D40ntdll.dllNo
0x844A2D785748Waiting0x81D52B000x7FFD60000x6666892Cwuaueng.dllNo
0x83F9E8B85300Waiting0x81D52B000x7FF960000x68CAEB65esent.dllNo
0x83F8B5405296Waiting0x81D52B000x7FF9D0000x68CAEB65esent.dllNo
0x863DBD784976Waiting0x81D52B400x7FF8D0000x7623F36Fadvapi32.dllNo
0x862019004872Waiting0x81D52B000x7FF940000x72903289ssdpapi.dllNo
0x8400B5384712Waiting0x81D52B400x7FF950000x76E55795ole32.dllNo
0x840953704660Waiting0x81D52B400x7FF970000x7623F36Fadvapi32.dllNo
0x84059D784160Waiting0x81D52B000x7FF890000x75D61EDEncobjapi.dllNo
0x85E73A784156Waiting0x81D52B000x7FF8A0000x75D61EDEncobjapi.dllNo
0x8403E6504140Waiting0x81D52B000x7FF8B0000x67CB3F11NCProv.dllNo
0x83FE95F03472Waiting0x81D52B400x7FF9B0000x77860148rpcrt4.dllNo
0x8639FA783508Waiting0x81D52B000x7FF980000x75D7743Aauthz.dllNo
0x862D72582772Waiting0x81D52B000x7FF990000x73004526aelupsvc.dllNo
0x85D320302768Waiting0x81D52B000x7FF9A0000x73004526aelupsvc.dllNo
0x862177C02408Waiting0x81D52B000x7FF9C0000x73DFA2E9gpsvc.dllNo
0x8613F7E0396Waiting0x81D52B000x7FFA50000x7623F36Fadvapi32.dllNo
0x860DED48464Waiting0x81D52B000x7FF9F0000x729125F9IKEEXT.DLLNo
0x860EAD78472Waiting0x81D52B000x7FFA00000x75D7743Aauthz.dllNo
0x85E2AAC01928Waiting0x81D52B000x7FFA30000x7300482Daelupsvc.dllNo
0x85E2AD781924Waiting0x81D52B000x7FFA40000x73003FA2aelupsvc.dllNo
0x85441C881728Waiting0x81D52B400x7FFA70000x731C9F25schedsvc.dllNo
0x854418781724Waiting0x81D52B000x7FFA80000x73261709taskcomp.dllNo
0x8542F0301716Waiting0x81D52B000x7FFA90000x731D05C9schedsvc.dllNo
0x85F10BF01712Waiting0x81D52B000x7FFAA0000x776C2D40ntdll.dllNo
0x854314A01708Waiting0x81D52B400x7FFAB0000x7623F36Fadvapi32.dllNo
0x854325501704Waiting0x81D52B400x7FFAC0000x7623F36Fadvapi32.dllNo
0x8542BB401684Waiting0x81D52B000x7FFAD0000x77252670msvcrt.dllNo
0x860220301668Waiting0x81D52B000x7FFAE0000x76E55795ole32.dllNo
0x85FF9A181664Waiting0x81D52B400x7FFD50000x7623F36Fadvapi32.dllNo
0x85FEAB681620Waiting0x81D52B000x7FFAF0000x73DFA2E9gpsvc.dllNo
0x85FCFD781420Waiting0x81D52B000x7FFD40000x7623F36Fadvapi32.dllNo
0x860280301388Waiting0x81D52B000x7FFD70000x776C2D40ntdll.dllNo
0x85FBE0301380Waiting0x81D52B000x7FFD80000x776C2808ntdll.dllNo
0x85FAF0301360Waiting0x81D52B000x7FFDA0000x7623F36Fadvapi32.dllNo
0x85FA9CB81268Waiting0x81D52B000x7FFDD0000x74414437mmcss.dllNo
0x85FA21881260Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x85F68B701220Waiting0x81D52B400x7FFDF0000x00E42083svchost.exeNo
audiodg.exe ( PID : 1304 )
0x842280305716Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863474C05188Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8416AAC04472Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x841720304468Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8416A7C04464Terminated0x81D52B000x73CF82B3AudioEng.dllNoTerminated
0x840524D04460Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E9BAC04456Terminated0x81D52B000x7391C206RtkAPO.dllNoTerminated
0x85E8E0304452Terminated0x81D52B000x7391C15FRtkAPO.dllNoTerminated
0x85E9BD784448Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x84166A784444Terminated0x81D52B000x739140DERtkAPO.dllNoTerminated
0x8416AD784440Terminated0x81D52B400x74501F72MMDevAPI.dllNoTerminated
0x840765F04204Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844F58205988Waiting0x81D52B000x7FFDD0000x77860148rpcrt4.dllNo
0x85FCD7A01508Waiting0x81D52B000x7FFD80000x776C2808ntdll.dllNo
0x85FA80301308Waiting0x81D52B400x7FFDE0000x00AA97DFaudiodg.exeNo
dllhost.exe ( PID : 1340 )
0x863416B02948Terminated0x81D52B400x77860148NoTerminated
0x83F664902588Terminated0x81D52B000x76E407A1NoTerminated
0x83F667483036Terminated0x81D52B400x76E55795NoTerminated
0x83F66A001244Terminated0x81D52B000x76E55795NoTerminated
0x83FE00301992Terminated0x81D52B400x77860148NoTerminated
TODDSrv.exe ( PID : 1356 )
0x861359A81628Waiting0x81D52B400x7FFDC0000x00402760TODDSrv.exeNo
0x86134A781604Waiting0x81D52B000x7FFDD0000x00401000TODDSrv.exeNo
0x86132C881516Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x86119D781416Waiting0x81D52B400x7FFDF0000x004049D2TODDSrv.exeNo
SLsvc.exe ( PID : 1364 )
0x83EDE2584080Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85FC05401476Waiting0x81D52B000x7FFDE0000x77252670msvcrt.dllNo
0x85FC7BB01456Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x85FC4B001448Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x85FAF7C01368Waiting0x81D52B400x7FFDF0000x00F25756SLsvc.exeNo
svchost.exe ( PID : 1428 )
0x84463D785812Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F875305284Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E903E05280Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85FBBD784960Terminated0x81D52B000x75D7743ANoTerminated
0x86216D784956Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x83F8EA104772Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840F43604752Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85481D784728Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F5F2304672Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x83F5EA782908Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8638ED783860Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x864964783776Terminated0x81D52B000x72902F1Bssdpapi.dllNoTerminated
0x8637DB203772Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8637D3903768Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8645DAC03764Terminated0x81D52B000x72902F1Bssdpapi.dllNoTerminated
0x864E68503756Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8647F8F83700Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x862AB9283696Terminated0x81D52B400x7623F36Fadvapi32.dllNoTerminated
0x862188E02432Terminated0x81D52B400x73B71960es.dllNoTerminated
0x8613BB001920Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x8606BD781888Terminated0x81D52B400x73B7BABDes.dllNoTerminated
0x841E17605596Waiting0x81D52B000x7FFDC0000x77860148rpcrt4.dllNo
0x8645D5303760Waiting0x81D52B000x7FFA20000x72903289ssdpapi.dllNo
0x864424A83752Waiting0x81D52B000x7FFA40000x691A8AC9fdSSDP.dllNo
0x86442D783748Waiting0x81D52B000x7FFA50000x691A8AC9fdSSDP.dllNo
0x8645DD783744Waiting0x81D52B000x7FFA60000x691A8AC9fdSSDP.dllNo
0x86458B103740Waiting0x81D52B000x7FFA90000x691A8AC9fdSSDP.dllNo
0x863127403708Waiting0x81D52B000x7FFA70000x6911B1DCssdpsrv.dllNo
0x8644AD783704Waiting0x81D52B000x7FFA80000x6911B2B8ssdpsrv.dllNo
0x862158B82436Waiting0x81D52B000x7FFAB0000x77860148rpcrt4.dllNo
0x861397582132Waiting0x81D52B400x7FFAE0000x717E80F4netprofm.dllNo
0x8615D3602128Waiting0x81D52B400x7FFAD0000x717E9C63netprofm.dllNo
0x861548B82088Waiting0x81D52B000x7FFD40000x776C2D40ntdll.dllNo
0x86145D782072Waiting0x81D52B000x7FFD30000x718CE833w32time.dllNo
0x8610ED78764Waiting0x81D52B000x7FFD50000x776C2D40ntdll.dllNo
0x86041CA8616Waiting0x81D52B000x7FFD60000x7623F36Fadvapi32.dllNo
0x8606B2B01876Waiting0x81D52B400x7FFDD0000x77860148rpcrt4.dllNo
0x860084501488Waiting0x81D52B000x7FFD80000x776C2D40ntdll.dllNo
0x860089681484Waiting0x81D52B000x7FFD90000x776C2808ntdll.dllNo
0x85FC6AC01464Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x85FCFAC01432Waiting0x81D52B400x7FFDE0000x00E42083svchost.exeNo
TosBtSrv.exe ( PID : 1492 )
0x86140808932Waiting0x81D52B000x7FFDD0000x00403D68TosBtSrv.exeNo
0x86139458816Waiting0x81D52B400x7FFDE0000x7623F36Fadvapi32.dllNo
0x86131C881548Waiting0x81D52B400x7FFDF0000x004084E1TosBtSrv.exeNo
Ati2evxx.exe ( PID : 1520 )
0x83FE1870804Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x860668581848Terminated0x81D52B000x00193990Ati2evxx.dllNoTerminated
0x860703901840Terminated0x81D52B400x0040C580Ati2evxx.exeNoTerminated
0x840D0A786000Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x8607FB701852Waiting0x81D52B400x7FFD90000x0040AC40Ati2evxx.exeNo
0x860709201836Waiting0x81D52B400x7FFDB0000x00428330Ati2evxx.exeNo
0x86070D781832Waiting0x81D52B000x7FFDC0000x00428DC0Ati2evxx.exeNo
0x860700301828Waiting0x81D52B000x7FFDD0000x00428DC0Ati2evxx.exeNo
0x85FE00301524Waiting0x81D52B400x7FFDE0000x00450CF9Ati2evxx.exeNo
SbieSvc.exe ( PID : 1528 )
0x85FDDD781580Waiting0x81D52B000x7FFD80000x0100467ESbieSvc.exeNo
0x85FE63481576Waiting0x81D52B000x7FFD90000x0100467ESbieSvc.exeNo
0x85FDD0301572Waiting0x81D52B000x7FFDA0000x0100467ESbieSvc.exeNo
0x85FE66001568Waiting0x81D52B000x7FFDB0000x0100467ESbieSvc.exeNo
0x85FE68B81564Waiting0x81D52B000x7FFDC0000x0100467ESbieSvc.exeNo
0x85FDF4501532Waiting0x81D52B400x7FFDF0000x0100DD78SbieSvc.exeNo
pfsvc.exe ( PID : 1640 )
0x8633C4B05124Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86020A805120Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86072D785116Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862A28685112Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8629E0305104Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85E67D785100Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863070305096Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862F4D005092Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862DEAC05088Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x862DD0305084Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863098F85080Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8630BB805076Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86154D785064Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85FDD5505056Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85F31C285052Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x861FC0305048Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EB8D785044Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863A10305040Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8615B4005024Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x86153D785020Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863AA0305012Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863726A85008Terminated0x81D52B000x744E1BE2wscapi.dllNoTerminated
0x85FBD2782216Waiting0x81D52B000x7FFDD0000x776C2D40ntdll.dllNo
0x860150301648Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x85FE89B01644Waiting0x81D52B400x7FFDF0000x004231B0pfsvc.exeNo
spoolsv.exe ( PID : 1768 )
0x840F40304284Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x83FBCD783116Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83FB10303088Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840760304208Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x862AD0302652Waiting0x81D52B000x7FFA80000x7149667Clocalspl.dllNo
0x8627A3502644Waiting0x81D52B000x7FFAA0000x71D3269Efundisc.dllNo
0x862436B02640Waiting0x81D52B400x7FFAB0000x71D31D3Bfundisc.dllNo
0x862778302632Waiting0x81D52B000x7FFAC0000x71D32875fundisc.dllNo
0x862768482628Waiting0x81D52B400x7FFAD0000x6F71146CWSDMon.dllNo
0x862564D82604Waiting0x81D52B400x7FFAF0000x6F9F1DFCusbmon.dllNo
0x86257B702564Waiting0x81D52B000x7FFD30000x77252670msvcrt.dllNo
0x862577502560Waiting0x81D52B000x7FFD40000x70121654tcpmon.dllNo
0x86251D782556Waiting0x81D52B000x7FFD50000x70121775tcpmon.dllNo
0x862557A82552Waiting0x81D52B000x7FFD60000x77252670msvcrt.dllNo
0x86255D782548Waiting0x81D52B000x7FFD70000x77252670msvcrt.dllNo
0x860410301792Waiting0x81D52B400x7FFD90000x000A3873spoolsv.exeNo
0x860552701784Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x860577F81780Waiting0x81D52B400x7FFDD0000x7623F36Fadvapi32.dllNo
0x86056D781776Waiting0x81D52B000x7FFDE0000x756C3391EMET.dllNo
0x860570301772Waiting0x81D52B000x7FFDF0000x000A9ED3spoolsv.exeNo
svchost.exe ( PID : 1796 )
0x85FDE0D05216Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86215B704856Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85E064584720Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83EC70304692Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x840F18C04232Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840E1D784228Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F380302272Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83EF3030860Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83EEF5582164Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863E19703912Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86058D781904Terminated0x81D52B400x72DE79BBMPSSVC.dllNoTerminated
0x844F88006008Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x860A9C30264Waiting0x81D52B000x7FF9D0000x72FE1267wdi.dllNo
0x860AA348256Waiting0x81D52B000x7FF9E0000x72FE1267wdi.dllNo
0x860AA600252Waiting0x81D52B000x7FF9F0000x72FE1267wdi.dllNo
0x860AA8B8224Waiting0x81D52B000x7FFA00000x72FE1267wdi.dllNo
0x860AAB70196Waiting0x81D52B000x7FFA10000x72FE1267wdi.dllNo
0x860AA030188Waiting0x81D52B000x7FFA20000x72FE1267wdi.dllNo
0x860A4600184Waiting0x81D52B000x7FFA30000x72FE1267wdi.dllNo
0x860A48B8192Waiting0x81D52B000x7FFA40000x72FE1267wdi.dllNo
0x860A4B70124Waiting0x81D52B000x7FFA50000x72FE1267wdi.dllNo
0x860A52902044Waiting0x81D52B000x7FFA60000x72FE1267wdi.dllNo
0x860A88282040Waiting0x81D52B400x7FFA70000x72E57CCCdps.dllNo
0x8606E9382036Waiting0x81D52B000x7FFA80000x72E513E0dps.dllNo
0x860A38082032Waiting0x81D52B000x7FFA90000x72E513E0dps.dllNo
0x860A3AC02028Waiting0x81D52B000x7FFAA0000x72E513E0dps.dllNo
0x860A3D782024Waiting0x81D52B000x7FFAB0000x72E513E0dps.dllNo
0x860A30302020Waiting0x81D52B000x7FFAC0000x72E513E0dps.dllNo
0x860A5B702016Waiting0x81D52B000x7FFAD0000x72E5351Fdps.dllNo
0x86094B701972Waiting0x81D52B000x7FFAE0000x7623F36Fadvapi32.dllNo
0x860786481964Waiting0x81D52B000x7FFAF0000x776C2D40ntdll.dllNo
0x860763F81948Waiting0x81D52B400x7FFD30000x72DE552DMPSSVC.dllNo
0x85E02D781916Waiting0x81D52B000x7FFD40000x72DF04FFMPSSVC.dllNo
0x860589281912Waiting0x81D52B000x7FFD50000x72DD8801MPSSVC.dllNo
0x860583A01908Waiting0x81D52B000x7FFDE0000x72DD8A06MPSSVC.dllNo
0x8605A5801900Waiting0x81D52B000x7FFD70000x75D7743Aauthz.dllNo
0x8605AD781884Waiting0x81D52B000x7FFD80000x75D7743Aauthz.dllNo
0x86042B181812Waiting0x81D52B000x7FFDC0000x75D7743Aauthz.dllNo
0x860422B81808Waiting0x81D52B000x7FFDD0000x776C2808ntdll.dllNo
0x860400301800Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
ULCDRSvr.exe ( PID : 1856 )
0x8613D7601896Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x8613CD301804Waiting0x81D52B000x7FFDF0000x00401BC6ULCDRSvr.exeNo
agrsmsvc.exe ( PID : 1940 )
0x860710301952Waiting0x81D52B000x7FFDE0000x7623F36Fadvapi32.dllNo
0x85E2A0301944Waiting0x81D52B400x7FFDF0000x01002226agrsmsvc.exeNo
svchost.exe ( PID : 1956 )
0x844CB2C05972Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844A40305768Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844954505764Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844756B05756Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x842107A85624Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863FA2285436Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83EC37285268Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x86137CF05132Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x863BBD784912Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x8419C0304588Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F3ED78784Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83EC72F04044Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83EC79684040Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x863B8D783944Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EFC7C83836Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x861369202100Terminated0x81D52B000x7624D5ECadvapi32.dllNoTerminated
0x8609B5182000Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x844EA6385908Waiting0x81D52B000x7FFDE0000x77860148rpcrt4.dllNo
0x85FB10304944Waiting0x81D52B000x7FFDB0000x69544B34msdtckrm.dllNo
0x863D96183716Waiting0x81D52B000x7FFAF0000x72903289ssdpapi.dllNo
0x86161AC02144Waiting0x81D52B000x7FFAC0000x77252670msvcrt.dllNo
0x86161D782140Waiting0x81D52B000x7FFAD0000x77252670msvcrt.dllNo
0x86158D782096Waiting0x81D52B000x7FFD60000x71887E8Bnlasvc.dllNo
0x86158A782092Waiting0x81D52B000x7FFD70000x776C2D40ntdll.dllNo
0x8609ED782008Waiting0x81D52B000x7FFDA0000x776C2808ntdll.dllNo
0x860796B81960Waiting0x81D52B400x7FFDF0000x00E42083svchost.exeNo
svchost.exe ( PID : 1968 )
0x8614FD782068Waiting0x81D52B000x7FFDB0000x776C2D40ntdll.dllNo
0x86142A782064Waiting0x81D52B000x7FFDC0000x71C4483Bwersvc.dllNo
0x861448D82056Waiting0x81D52B000x7FFDD0000x776C2808ntdll.dllNo
0x86139C601996Waiting0x81D52B000x7FFDF0000x00E42083svchost.exeNo
PresentationFontCache.exe ( PID : 1980 )
0x860D0030324Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x860AF108308Terminated0x81D52B000x7623F36Fadvapi32.dllNoTerminated
0x860E0890476Waiting0x81D52B000x7FFDA0000x720D9B17mscorwks.dllNo
0x860AEB70300Waiting0x81D52B000x7FFDD0000x720D9B17mscorwks.dllNo
0x860A5568304Waiting0x81D52B000x7FFDE0000x72055DEFmscorwks.dllNo
0x860977401984Waiting0x81D52B400x7FFDF0000x0004746EPresentationFontCache.exeNo
taskeng.exe ( PID : 2228 )
0x844E43985880Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x844D6CC05848Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x844B24985828Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x841ED4685824Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8444B8085684Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x8421F0305628Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x842120305608Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x842115585604Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E9A7785388Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x840075485356Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x840872305324Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x83F4D5505320Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863548B04900Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x862F40304896Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x84026AC04700Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x862D9D784684Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83FBE0302968Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x83F927D01104Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x83F8D6802904Terminated0x81D52B000x00211D70taskeng.exeNoTerminated
0x83F8E0302944Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8416ECF86016Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x861BAD782240Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x861BA9282236Waiting0x81D52B000x7FFDD0000x776C2D40ntdll.dllNo
0x8543FA282232Waiting0x81D52B400x7FFDF0000x0021B28Ftaskeng.exeNo
dllhost.exe ( PID : 2404 )
0x83FD4D002980Terminated0x81D52B400x77860148NoTerminated
0x840160303012Terminated0x81D52B000x76E407A1NoTerminated
0x83FDDD783016Terminated0x81D52B400x76E55795NoTerminated
0x84016D781440Terminated0x81D52B000x76E55795NoTerminated
0x83FDD3E02468Terminated0x81D52B400x77860148NoTerminated
taskeng.exe ( PID : 2460 )
0x841576504340Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x840F4D784288Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x83F833003168Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x841D3D786024Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x8631E9703272Waiting0x81D52B400x7FFAA0000x6E191C38TMM.dllNo
0x862FB0302928Waiting0x81D52B400x7FFAC0000x6E19A4FBTMM.dllNo
0x862DF4B02812Waiting0x81D52B400x7FFAD0000x00211D70taskeng.exeNo
0x862538C02540Waiting0x81D52B400x7FFAE0000x770B5571msctf.dllNo
0x862530302528Waiting0x81D52B400x7FFD30000x745713DDwinmm.dllNo
0x862529682524Waiting0x81D52B400x7FFD40000x701A20FEMsCtfMonitor.dllNo
0x862439682504Waiting0x81D52B400x7FFD50000x00211D70taskeng.exeNo
0x8623F7802500Waiting0x81D52B400x7FFD60000x00211D70taskeng.exeNo
0x8606F5C02496Waiting0x81D52B400x7FFD70000x71531963HotStartUserAgent.dllNo
0x8623BD782492Waiting0x81D52B000x7FFD80000x00211D70taskeng.exeNo
0x86232AC02476Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x86232D782472Waiting0x81D52B000x7FFDD0000x776C2D40ntdll.dllNo
0x862300302464Waiting0x81D52B400x7FFDE0000x0021B28Ftaskeng.exeNo
dwm.exe ( PID : 2508 )
0x86275A102636Waiting0x81D52B000x7FFD80000x776C2D40ntdll.dllNo
0x861830302620Waiting0x81D52B000x7FFD90000x776C2D40ntdll.dllNo
0x86259B702608Waiting0x81D52B400x7FFDB0000x6F9B8B2FuDWM.dllNo
0x862550302600Waiting0x81D52B400x7FFDC0000x6FF88A55milcore.dllNo
0x862501E02520Waiting0x81D52B000x7FFDD0000x776C2808ntdll.dllNo
0x862504982516Waiting0x81D52B400x7FFDE0000x00DA5007dwm.exeNo
0x8624E9682512Waiting0x81D52B400x7FFDF0000x00DA538Ddwm.exeNo
explorer.exe ( PID : 2612 )
0x85DFC7806040Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x84025D786032Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x844AF0305844Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x844AFD785820Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x84212D785600Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x841A5A805536Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x860374E85292Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x862A64085108Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x85EF20305068Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8613A8505036Terminated0x81D52B000x776C2D40ntdll.dllNoTerminated
0x8609F0305016Terminated0x81D52B000x744E1BE2wscapi.dllNoTerminated
0x8417DD784696Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x8413A7604300Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x840F04A84296Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x840F35504280Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x840C09384220Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405E7504168Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405CAC04136Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405CD784132Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8403ED784128Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x85E73D784124Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x85547D784120Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x84038A784116Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405D6A81408Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405D0301436Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405DD783080Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8405D9603084Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x84029D783292Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83FDC9783296Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x8404F8883312Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x8404F270808Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x8403BC882680Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x83FB8768296Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x83F9EB701412Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83FA35281352Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83FA1AC81200Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83FA0D781192Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83FA29D82168Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83F44B701240Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x83F965682360Terminated0x81D52B400x776C2D40ntdll.dllNoTerminated
0x83F940303044Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x83F8E5682956Terminated0x81D52B400x7756C224shlwapi.dllNoTerminated
0x864654E84008Terminated0x81D52B000x7756C224shlwapi.dllNoTerminated
0x864385183988Terminated0x81D52B400x77860148rpcrt4.dllNoTerminated
0x84082D786036Waiting0x81D52B400x7FFDC0000x77860148rpcrt4.dllNo
0x8405D3F0156Waiting0x81D52B400x7FF910000x6F773AC8browseui.dllNo
0x84027D783000Waiting0x81D52B400x7FFDD0000x7756C224shlwapi.dllNo
0x83F818701196Waiting0x81D52B400x7FFD60000x6F773AC8browseui.dllNo
0x864195303808Waiting0x81D52B400x7FF960000x7756C224shlwapi.dllNo
0x864657C83692Waiting0x81D52B400x7FF9A0000x71D32875fundisc.dllNo
0x8638E0303484Waiting0x81D52B400x7FF970000x7756C224shlwapi.dllNo
0x8638B7583476Waiting0x81D52B000x7FF990000x76E55795ole32.dllNo
0x863775A03468Waiting0x81D52B400x7FF9B0000x7756C224shlwapi.dllNo
0x86376B703464Waiting0x81D52B400x7FF9C0000x7756C224shlwapi.dllNo
0x8637EBC03460Waiting0x81D52B400x7FF9D0000x7756C224shlwapi.dllNo
0x863665783456Waiting0x81D52B400x7FF9E0000x7756C224shlwapi.dllNo
0x863779683448Waiting0x81D52B400x7FF9F0000x6C5649D9wlanapi.dllNo
0x86372B703444Waiting0x81D52B000x7FFA00000x776C2D40ntdll.dllNo
0x863405383424Waiting0x81D52B400x7FFA20000x7756C224shlwapi.dllNo
0x86343A303420Waiting0x81D52B400x7FFA30000x6CB015A2SndVolSSO.dllNo
0x863400303416Waiting0x81D52B000x7FFA40000x6CB025C2SndVolSSO.dllNo
0x863199683412Waiting0x81D52B400x7FFA50000x74501F72MMDevAPI.dllNo
0x8635FD783400Waiting0x81D52B000x7FFA60000x776C2808ntdll.dllNo
0x863419683396Waiting0x81D52B400x7FFA70000x77252670msvcrt.dllNo
0x863545B03392Waiting0x81D52B400x7FFA80000x7756C224shlwapi.dllNo
0x863410303388Waiting0x81D52B400x7FFAD0000x6C74B2E0stobject.dllNo
0x862DBA902916Waiting0x81D52B400x7FFAF0000x7756C224shlwapi.dllNo
0x862DED782864Waiting0x81D52B000x7FFAA0000x743B7E7Ewdmaud.drvNo
0x862DC0302776Waiting0x81D52B000x7FFAE0000x6E8C17AEmsiltcfg.dllNo
0x86292D782724Waiting0x81D52B400x7FFD90000x746C7456GdiPlus.dllNo
0x8628D4882712Waiting0x81D52B400x7FFDA0000x7756C224shlwapi.dllNo
0x8622F7182704Waiting0x81D52B400x7FFDB0000x7756C224shlwapi.dllNo
0x862596E82616Waiting0x81D52B400x7FFDE0000x00A75E33explorer.exeNo
RtHDVCpl.exe ( PID : 2760 )
0x840F30304264Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x86328D783232Waiting0x81D52B000x7FFD60000x77860148rpcrt4.dllNo
0x8631D6D03176Waiting0x81D52B000x7FFD70000x00424EC0RtHDVCpl.exeNo
0x85F697683140Waiting0x81D52B000x7FFD80000x776C2808ntdll.dllNo
0x85FC00303124Waiting0x81D52B400x7FFD90000x74501F72MMDevAPI.dllNo
0x85C63D783112Waiting0x81D52B400x7FFDA0000x00483B53RtHDVCpl.exeNo
0x85C08D783100Waiting0x81D52B400x7FFDB0000x00483B53RtHDVCpl.exeNo
0x8631BB503092Waiting0x81D52B400x7FFDC0000x00483B53RtHDVCpl.exeNo
0x863238C02988Waiting0x81D52B400x7FFDD0000x746C7456GdiPlus.dllNo
0x862C94F02764Waiting0x81D52B400x7FFDE0000x0047FDE0RtHDVCpl.exeNo
SynTPStart.exe ( PID : 2780 )
0x840F2D784252Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x85EC2D784016Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85F544783108Waiting0x81D52B000x7FFDC0000x77860148rpcrt4.dllNo
0x862D7A782784Waiting0x81D52B400x7FFDE0000x00402410SynTPStart.exeNo
AntiLogger.exe ( PID : 2824 )
0x844F98785924Terminated0x81D52B400x00416600AntiLogger.exeNoTerminated
0x855533484680Terminated0x81D52B400x00439AACAntiLogger.exeNoTerminated
0x8630C7C04676Terminated0x81D52B400x00439AACAntiLogger.exeNoTerminated
0x840DA9884580Terminated0x81D52B400x00439AACAntiLogger.exeNoTerminated
0x840F07604260Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x84026D783052Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8637D8683780Terminated0x81D52B400x00439AACAntiLogger.exeNoTerminated
0x862147C03664Terminated0x81D52B000x00484C20AntiLogger.exeNoTerminated
0x862036A83668Waiting0x81D52B000x7FFD50000x00439850AntiLogger.exeNo
0x8615C3883660Waiting0x81D52B000x7FFD70000x00422BDCAntiLogger.exeNo
0x860A02003584Waiting0x81D52B000x7FFD80000x77860148rpcrt4.dllNo
0x863A60303544Waiting0x81D52B000x7FFD90000x776C2808ntdll.dllNo
0x8639AC303540Waiting0x81D52B000x7FFDA0000x776C2D40ntdll.dllNo
0x85FDE7E83328Waiting0x81D52B400x7FFDC0000x00484C20AntiLogger.exeNo
0x8630A5902984Waiting0x81D52B000x7FFDE0000x756C3391EMET.dllNo
0x85FC89902828Waiting0x81D52B400x7FFDF0000x00401AF8AntiLogger.exeNo
PFGUI.exe ( PID : 2832 )
0x855460304764Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840520304436Terminated0x81D52B000x75840735crypt32.dllNoTerminated
0x840F3AC04272Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x83FD1CF03156Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x864AA4E83956Terminated0x81D52B000x75840735crypt32.dllNoTerminated
0x85EC20303840Terminated0x81D52B000x0044FAAEPFGUI.exeNoTerminated
0x862AC1283732Terminated0x81D52B000x0044FAAEPFGUI.exeNoTerminated
0x862DBD786044Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x863A77103576Waiting0x81D52B400x7FFAE0000x6C18D7EEmshtml.dllNo
0x86327D783504Waiting0x81D52B000x7FFAF0000x00419F6EPFGUI.exeNo
0x863913B83492Waiting0x81D52B000x7FFD30000x004215F6PFGUI.exeNo
0x8543B5F03324Waiting0x81D52B400x7FFD40000x6C18D7EEmshtml.dllNo
0x86316D783072Waiting0x81D52B000x7FFD50000x6CD1A356msjet40.dllNo
0x863178183068Waiting0x81D52B000x7FFD60000x6CD1A356msjet40.dllNo
0x8637F0303064Waiting0x81D52B000x7FFD70000x6CD1A356msjet40.dllNo
0x863174083060Waiting0x81D52B400x7FFD80000x6CE2F704msjet40.dllNo
0x863159A03056Waiting0x81D52B000x7FFD90000x6CEB6BCDcomsvcs.dllNo
0x862F59002996Waiting0x81D52B000x7FFDC0000x776C2808ntdll.dllNo
0x862F50302992Waiting0x81D52B000x7FFDD0000x776C2D40ntdll.dllNo
0x862E0D782836Waiting0x81D52B400x7FFDE0000x0047D8F1PFGUI.exeNo
jusched.exe ( PID : 2840 )
0x840F38084276Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x862F67C82852Waiting0x81D52B000x7FFDD0000x756C3391EMET.dllNo
0x862E03682844Waiting0x81D52B400x7FFDE0000x0041538Cjusched.exeNo
TOSCDSPD.exe ( PID : 2856 )
0x840F3D784268Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x862DD9502860Waiting0x81D52B400x7FFDF0000x004023B0TOSCDSPD.exeNo
SbieCtrl.exe ( PID : 2872 )
0x840F2AC04256Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x83FEBD782388Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8446B6786048Waiting0x81D52B000x7FFDC0000x77860148rpcrt4.dllNo
0x85FAB6B83104Waiting0x81D52B400x7FFDE0000x746C7456GdiPlus.dllNo
0x862F3D782876Waiting0x81D52B400x7FFDF0000x01037A9BSbieCtrl.exeNo
rundll32.exe ( PID : 2900 )
0x83F924301184Terminated0x81D52B000x77860148NoTerminated
0x83F96D781204Terminated0x81D52B000x776C2D40NoTerminated
rundll32.exe ( PID : 2960 )
0x83F9B0302792Terminated0x81D52B000x77860148NoTerminated
0x83F9BD782912Terminated0x81D52B000x776C2D40NoTerminated
MOM.exe ( PID : 3004 )
0x840E86B04248Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x83FEA2A02376Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x863CEA283980Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x863C74183972Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x864B80303964Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x8635F0303408Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x8635F8B83404Waiting0x81D52B000x7FF4E0000x7223C134mscorwks.dllNo
0x8633B5903244Waiting0x81D52B000x7FF4F0000x71FC4467mscorwks.dllNo
0x8633AA983240Waiting0x81D52B000x7FFD30000x720D9B17mscorwks.dllNo
0x8631A4883200Waiting0x81D52B400x7FFD40000x720D9B17mscorwks.dllNo
0x8543C0303188Waiting0x81D52B000x7FFD50000x71FB75E6mscorwks.dllNo
0x8543AB183184Waiting0x81D52B000x7FFD70000x720D9B17mscorwks.dllNo
0x86308CD03180Waiting0x81D52B000x7FFD80000x720D9B17mscorwks.dllNo
0x85EBB9003164Waiting0x81D52B000x7FFD90000x720D9B17mscorwks.dllNo
0x863075903152Waiting0x81D52B000x7FFDA0000x77860148rpcrt4.dllNo
0x8631CD783136Waiting0x81D52B400x7FFDB0000x720D9B17mscorwks.dllNo
0x85F277183120Waiting0x81D52B400x7FFDC0000x720D9B17mscorwks.dllNo
0x863209683096Waiting0x81D52B000x7FFDD0000x720D9B17mscorwks.dllNo
0x8637F7D03076Waiting0x81D52B000x7FFDE0000x72055DEFmscorwks.dllNo
0x86323D783008Waiting0x81D52B400x7FFDF0000x00FB308EMOM.exeNo
consent.exe ( PID : 3160 )
0x83FF3A983208Terminated0x81D52B400x776C2D40NoTerminated
0x83FF09203236Terminated0x81D52B000x77860148NoTerminated
0x83FB23203212Terminated0x81D52B000x75840735NoTerminated
0x83FC2D003172Terminated0x81D52B000x776C2D40NoTerminated
0x83FD90303148Terminated0x81D52B400x00A3327ENoTerminated
AntiLogger.exe ( PID : 3216 )
0x8631ED783220Terminated0x81D52B400x00401AF8NoTerminated
dllhost.exe ( PID : 3224 )
0x83FF1D783452Terminated0x81D52B000x77860148NoTerminated
0x83FD16303376Terminated0x81D52B000x76E407A1NoTerminated
0x83FDA9C03348Terminated0x81D52B400x76E55795NoTerminated
0x83FCB7F83356Terminated0x81D52B000x76E55795NoTerminated
0x83FED0303308Terminated0x81D52B400x77860148NoTerminated
SynTPEnh.exe ( PID : 3264 )
0x840E89684244Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x86353D783384Waiting0x81D52B000x7FFDD0000x1000AD92SynCOM.dllNo
0x863274A83380Waiting0x81D52B000x7FFDB0000x77860148rpcrt4.dllNo
0x863A90303352Waiting0x81D52B400x7FFDC0000x00419FE0SynTPEnh.exeNo
0x85439D783284Waiting0x81D52B400x7FFDE0000x1000AF4CSynCOM.dllNo
0x8543EB203268Waiting0x81D52B400x7FFDF0000x00441A84SynTPEnh.exeNo
CCC.exe ( PID : 3276 )
0x844A94B86092Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x844F34385996Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x8421F4D05944Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x84086A805784Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x8448C7985736Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x842270305712Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x841A9D785544Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x855445485432Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x841F42A85412Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x863630305232Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x861613505148Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x83FE33704760Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x841796B84584Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x840D64A84520Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x84171A604476Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x840D6D784424Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x8406ED784200Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x83F7F0302924Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x83F3F6E81588Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x85E900304024Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x863CED783948Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x85EACB703940Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x85EAC3F83932Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x85EABD783928Terminated0x81D52B000x720D9B17mscorwks.dllNoTerminated
0x863CD2403924Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863DB5B83920Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863E0D783916Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863C6D783908Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863E66703904Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x86390D783900Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x860272A03896Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x85EAC0303892Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x8646B2883888Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x86439B983884Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863219703880Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863FCC083872Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863F8A203864Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863C6A783856Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863F81983848Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863220303844Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x85E21A483832Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863B2B103828Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x86419B703824Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x860C57383820Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863FB6C83816Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x864021A03812Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863B8A283804Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863B80303800Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x863F58D03796Terminated0x81D52B000x76E55795ole32.dllNoTerminated
0x863F23C83792Terminated0x81D52B400x720D9B17mscorwks.dllNoTerminated
0x86239D786068Waiting0x81D52B000x7FF490000x77860148rpcrt4.dllNo
0x85FCCD786072Waiting0x81D52B000x7FF4A0000x77860148rpcrt4.dllNo
0x85EA42C06060Waiting0x81D52B000x7FFD40000x720D9B17mscorwks.dllNo
0x844EF0306056Waiting0x81D52B400x7FFD70000x77860148rpcrt4.dllNo
0x854817403984Waiting0x81D52B400x7FF420000x720D9B17mscorwks.dllNo
0x85EAB9583976Waiting0x81D52B400x7FF430000x720D9B17mscorwks.dllNo
0x864B87D83968Waiting0x81D52B400x7FF440000x720D9B17mscorwks.dllNo
0x863C7D783960Waiting0x81D52B000x7FF450000x720D9B17mscorwks.dllNo
0x864387D03868Waiting0x81D52B000x7FF480000x71FC4467mscorwks.dllNo
0x863F60303788Waiting0x81D52B400x7FF4B0000x720D9B17mscorwks.dllNo
0x8646B7083784Waiting0x81D52B400x7FF4C0000x720D9B17mscorwks.dllNo
0x863BB5583736Waiting0x81D52B400x7FF4D0000x720D9B17mscorwks.dllNo
0x86438AB83728Waiting0x81D52B400x7FF4E0000x746C7456GdiPlus.dllNo
0x8632A6C83724Waiting0x81D52B400x7FF4F0000x720D9B17mscorwks.dllNo
0x863D99903712Waiting0x81D52B000x7FFD30000x720D9B17mscorwks.dllNo
0x86287D783372Waiting0x81D52B000x7FFD50000x7223C134mscorwks.dllNo
0x8631CAC03368Waiting0x81D52B400x7FFD60000x720D9B17mscorwks.dllNo
0x86364D783360Waiting0x81D52B400x7FFD80000x77860148rpcrt4.dllNo
0x863BBAC03344Waiting0x81D52B000x7FFD90000x71FB75E6mscorwks.dllNo
0x863D32703336Waiting0x81D52B000x7FFDC0000x720D9B17mscorwks.dllNo
0x8633E9683300Waiting0x81D52B400x7FFDD0000x720D9B17mscorwks.dllNo
0x8633B9683288Waiting0x81D52B000x7FFDE0000x72055DEFmscorwks.dllNo
0x86324D783280Waiting0x81D52B400x7FFDF0000x00A2307ECCC.exeNo
SynToshiba.exe ( PID : 3316 )
0x840F0D784240Terminated0x81D52B000x7768F67Bntdll.dllNoTerminated
0x8543B8A83320Waiting0x81D52B400x7FFDF0000x0040391BSynToshiba.exeNo
SynTPEnh.exe ( PID : 3488 )
0x83FF42B03248Terminated0x81D52B400x00441A84NoTerminated
WmiPrvSE.exe ( PID : 3532 )
0x841910304616Terminated0x81D52B000x77860148NoTerminated
0x855479884152Terminated0x81D52B000x75D61EDENoTerminated
0x84037A401096Terminated0x81D52B000x77860148NoTerminated
WmiPrvSE.exe ( PID : 3592 )
0x840589704796Terminated0x81D52B000x776C2D40NoTerminated
0x858CC0304640Terminated0x81D52B000x77860148NoTerminated
0x840F25584236Terminated0x81D52B000x7768F67BNoTerminated
0x8403E3984144Terminated0x81D52B000x75D61EDENoTerminated
0x863C59203952Terminated0x81D52B000x6975B765NoTerminated
0x862140303684Terminated0x81D52B000x77860148NoTerminated
WmiApSrv.exe ( PID : 3652 )
0x8400C0302676Terminated0x81D52B000x77860148NoTerminated
0x8641A3783720Terminated0x81D52B000x7624D5ECNoTerminated
0x85EF1C683680Terminated0x81D52B000x76E55795NoTerminated
0x86465D783676Terminated0x81D52B000x77860148NoTerminated
0x8645CA603672Terminated0x81D52B400x7623F36FNoTerminated
dllhost.exe ( PID : 4304 )
0x8413E7584332Terminated0x81D52B000x77860148NoTerminated
0x8413BD784328Terminated0x81D52B000x76E407A1NoTerminated
0x840D1D784320Terminated0x81D52B400x76E55795NoTerminated
0x8413ED784316Terminated0x81D52B000x76E55795NoTerminated
0x841447684312Terminated0x81D52B400x77860148NoTerminated
consent.exe ( PID : 4364 )
0x84169AC04432Terminated0x81D52B400x77252670NoTerminated
0x8416C6A84428Terminated0x81D52B400x743B7E7ENoTerminated
0x84164D784420Terminated0x81D52B400x745713DDNoTerminated
0x841693704408Terminated0x81D52B400x00A312F9NoTerminated
0x8416C9604400Terminated0x81D52B400x776C2D40NoTerminated
0x841674584396Terminated0x81D52B000x77860148NoTerminated
0x8416C0304388Terminated0x81D52B000x75840735NoTerminated
0x83F52D784380Terminated0x81D52B000x776C2D40NoTerminated
0x83F9AA984376Terminated0x81D52B400x770B5571NoTerminated
0x840E45184372Terminated0x81D52B400x701A26EANoTerminated
0x841533484368Terminated0x81D52B400x00A3327ENoTerminated
dllhost.exe ( PID : 4484 )
0x841799704508Terminated0x81D52B000x77860148NoTerminated
0x841790304504Terminated0x81D52B000x76E407A1NoTerminated
0x841784184500Terminated0x81D52B400x76E55795NoTerminated
0x841726104496Terminated0x81D52B000x76E55795NoTerminated
0x841765104492Terminated0x81D52B400x77860148NoTerminated
dllhost.exe ( PID : 4512 )
0x840D60304544Terminated0x81D52B000x77860148NoTerminated
0x8417C5E84540Terminated0x81D52B000x76E407A1NoTerminated
0x841700304536Terminated0x81D52B400x76E55795NoTerminated
0x841774A84532Terminated0x81D52B000x76E55795NoTerminated
0x841770304524Terminated0x81D52B400x77860148NoTerminated
Vba32arkit.exe ( PID : 4552 )
0x8409E7A86012Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x841E8D785936Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x840C40305792Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x8447ED785732Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x83F987C05260Terminated0x81D52B000x75840735crypt32.dllNoTerminated
0x83F68AD85248Terminated0x81D52B000x76E55795ole32.dllNoTerminated
0x85E712585244Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x841F80305588Waiting0x81D52B000x7FFAC0000x77860148rpcrt4.dllNo
0x8415CD785236Running0x81D52B400x7FFD40000x01330102Vba32arkit.exeNo
0x8638BAD85180Waiting0x81D52B000x7FFD50000x776C2D40ntdll.dllNo
0x8648A0305176Waiting0x81D52B000x7FFD60000x726D1C1Ddxtrans.dllNo
0x841B0D785172Waiting0x81D52B000x7FFD70000x726D1C1Ddxtrans.dllNo
0x8607F8B85168Waiting0x81D52B000x7FFD80000x726D1C1Ddxtrans.dllNo
0x861389F05164Waiting0x81D52B000x7FFD90000x726D1C1Ddxtrans.dllNo
0x86146D785160Waiting0x81D52B000x7FFDA0000x776C2808ntdll.dllNo
0x8414E9685156Waiting0x81D52B000x7FFDB0000x776C2D40ntdll.dllNo
0x8619FB505152Waiting0x81D52B000x7FFDC0000x6C18D7EEmshtml.dllNo
0x8418A9484636Waiting0x81D52B000x7FFDD0000x01330102Vba32arkit.exeNo
0x84061D784572Running0x81D52B400x7FFDE0000x012A4AE0Vba32arkit.exeNo
0x8403DD784556Waiting0x81D52B400x7FFDF0000x01402FB0Vba32arkit.exeNo
ctfmon.exe ( PID : 4564 )
0x841648084576Terminated0x81D52B400x770B5571NoTerminated
0x841709A04568Terminated0x81D52B400x006014F7NoTerminated
ctfmon.exe ( PID : 4644 )
0x841630304652Waiting0x81D52B400x7FFDE0000x770B5571msctf.dllNo
0x83F5A6004648Waiting0x81D52B400x7FFDF0000x007814F7ctfmon.exeNo
rundll32.exe ( PID : 4704 )
0x8626AB704860Terminated0x81D52B000x77860148NoTerminated
0x860B1D784848Terminated0x81D52B000x776C2D40NoTerminated
WmiPrvSE.exe ( PID : 4828 )
0x862A04F04880Terminated0x81D52B000x76E55795ole32.dllNoTerminated
0x864019504844Terminated0x81D52B000x77860148rpcrt4.dllNoTerminated
0x861730304892Waiting0x81D52B000x7FFD80000x7624D5ECadvapi32.dllNo
0x86291CF04888Waiting0x81D52B000x7FFD90000x77860148rpcrt4.dllNo
0x862A88484884Waiting0x81D52B400x7FFDA0000x00C7674FWmiPrvSE.exeNo
0x860D83104840Waiting0x81D52B000x7FFDD0000x75D61EDEncobjapi.dllNo
0x860A2B604832Waiting0x81D52B400x7FFDE0000x00C7F87BWmiPrvSE.exeNo
rundll32.exe ( PID : 4904 )
0x863C40304928Terminated0x81D52B000x77860148NoTerminated
0x863A4D784920Terminated0x81D52B000x776C2D40NoTerminated
WmiPrvSE.exe ( PID : 5456 )
0x841DFD785488Terminated0x81D52B400x00C7674FNoTerminated
0x83F494C05484Terminated0x81D52B000x76E55795NoTerminated
0x854800305476Terminated0x81D52B000x77860148NoTerminated
0x854807985472Terminated0x81D52B000x75D61EDENoTerminated
WMIADAP.exe ( PID : 5548 )
0x841D70305568Terminated0x81D52B000x76E55795NoTerminated
0x83FDFC505564Terminated0x81D52B000x77860148NoTerminated
0x840C3B705560Terminated0x81D52B400x00D054D1NoTerminated
WmiPrvSE.exe ( PID : 5648 )
0x84454B505680Terminated0x81D52B000x76E55795NoTerminated
0x84224D785676Terminated0x81D52B000x77860148NoTerminated
0x84453D785672Terminated0x81D52B000x75D61EDENoTerminated
Total:
Up

Modules

Don't display trusted items

BaseSizeTypeFull PathInformation
System ( PID : 4 ) - 156 Modules
0x8B19F00016.00 KbImage
C:\Windows\system32\DRIVERS\CmBatt.sys ( \Driver\CmBatt [0x85477030] )
Signed
0x8B09B00076.00 KbImage
C:\Windows\system32\DRIVERS\i8042prt.sys ( \Driver\i8042prt [0x85463E90] )
Signed
0x8B0B9000180.00 KbImage
C:\Windows\system32\DRIVERS\SynTP.sys ( \Driver\SynTP [0x854C2A08] )
Signed
0x8BE5A00036.00 KbImage
C:\Windows\system32\DRIVERS\hidusb.sys ( \Driver\HidUsb [0x8588CF38] )
Signed
0x9485E00040.00 KbImage
C:\Windows\system32\DRIVERS\ndisuio.sys ( \Driver\Ndisuio [0x85DF2BB8] )
Signed
0x8BE20000140.00 KbImage
C:\Program Files\AntiLogger\AntiLog32.sys ( \Driver\AntiLog32 [0x8585B640] )
Signed
0x8BE84000280.00 KbImage
C:\Windows\system32\DRIVERS\RTL8187B.sys ( \Driver\RTL8187B [0x858C2668] )
Signed
0x8BB99000136.00 KbImage
C:\Windows\system32\DRIVERS\VBoxDrv.sys ( \Driver\VBoxDrv [0x858EF4C8] )
Signed
0x8BA7D000288.00 KbImage
C:\Windows\system32\drivers\afd.sys ( \Driver\AFD [0x85780478] )
Signed
0x8B111000104.00 KbImage
C:\Windows\system32\DRIVERS\sdbus.sys ( \Driver\sdbus [0x8548BB28] )
Signed
0x81C1B0003.72 MbImage
C:\Windows\system32\ntkrnlpa.exe ( \Driver\PnpManager [0x839A4A50] )
Signed
0x80544000496.00 KbImage
C:\Windows\system32\drivers\Wdf01000.sys ( \Driver\Wdf01000 [0x846EEE70] )
Signed
0x8060D000280.00 KbImage
C:\Windows\system32\drivers\acpi.sys ( \Driver\ACPI [0x846EE6F8] )
Signed
0x8B00E000564.00 KbImage
C:\Windows\system32\DRIVERS\HDAudBus.sys ( \Driver\HDAudBus [0x854CCBE0] )
Signed
0x8AD28000636.00 KbImage
C:\Windows\System32\drivers\dxgkrnl.sys ( \Driver\DXGKrnl [0x85469298] )
Signed
0x8BB13000368.00 KbImage
C:\Windows\system32\DRIVERS\pwipf6.sys ( \Driver\pwipf6 [0x857E85B8] )
Signed
0x8B1F400044.00 KbImage
C:\Windows\system32\DRIVERS\ndistapi.sys ( \Driver\NdisTapi [0x8547D338] )
Signed
0x8068B00060.00 KbImage
C:\Windows\System32\drivers\partmgr.sys ( \Driver\partmgr [0x846FAB08] )
Signed
0x873C7000140.00 KbImage
C:\Windows\system32\DRIVERS\ndiswan.sys ( \Driver\NdisWan [0x85532240] )
Signed
0x80664000156.00 KbImage
C:\Windows\system32\drivers\pci.sys ( \Driver\pci [0x83DA2CA8] )
Signed
0x875E300068.00 KbImage
C:\Windows\system32\drivers\disk.sys ( \Driver\disk [0x849228A8] )
Signed
0x8ADEC00016.00 KbImage
C:\Windows\system32\DRIVERS\tdcmdpst.sys ( \Driver\tdcmdpst [0x8545DD30] )
Signed
0x8B7ED00028.00 KbImage
C:\Windows\System32\Drivers\Null.SYS ( \Driver\Null [0x85748410] )
Signed
0x8ADDD00060.00 KbImage
C:\Windows\system32\DRIVERS\usbehci.sys ( \Driver\usbehci [0x8547EF38] )
Signed
0x875A600028.00 KbImage
C:\Windows\system32\DRIVERS\pssnap.sys ( \Driver\pssnap [0x8480C680] )
Signed
0x9482400064.00 KbImage
C:\Windows\system32\DRIVERS\lltdio.sys ( \Driver\lltdio [0x85FEA868] )
Signed
0x8BB7D00076.00 KbImage
C:\Windows\system32\DRIVERS\wanarp.sys ( \Driver\Wanarpv6 [0x857DF968] )
Signed
0x8B60000040.00 KbImage
C:\Windows\system32\drivers\nsiproxy.sys ( \Driver\nsiproxy [0x857F7478] )
Signed
0x8B13A00080.00 KbImage
C:\Windows\system32\DRIVERS\rimsptsk.sys ( \Driver\rimsptsk [0x854F4490] )
Signed
0x806A700060.00 KbImage
C:\Windows\system32\drivers\volmgr.sys ( \Driver\volmgr [0x84714268] )
Signed
0x87515000228.00 KbImage
C:\Windows\system32\drivers\volsnap.sys ( \Driver\volsnap [0x84805B10] )
Signed
0x948E600084.00 KbImage
C:\Windows\System32\drivers\mpsdrv.sys ( \Driver\mpsdrv [0x8605A118] )
Signed
0x8BE7300036.00 KbImage
C:\Windows\system32\DRIVERS\kbdhid.sys ( \Driver\kbdhid [0x85870F38] )
Signed
0x87201000928.00 KbImage
C:\Windows\System32\drivers\tcpip.sys ( \Driver\Tcpip [0x846F7728] )
Signed
0x9486800076.00 KbImage
C:\Windows\system32\DRIVERS\rspndr.sys ( \Driver\rspndr [0x85FFBAF8] )
Signed
0x8BA5300088.00 KbImage
C:\Windows\system32\DRIVERS\tdx.sys ( \Driver\tdx [0x8577D478] )
Signed
0x8B44D0001.11 MbImage
C:\Windows\system32\DRIVERS\AGRSM.sys ( \Driver\AgereSoftModem [0x856FE318] )
Signed
0x8070000028.00 KbImage
C:\Windows\system32\drivers\pciide.sys ( \Driver\pciide [0x847157D8] )
Signed
0x8B1A3000188.00 KbImage
C:\Windows\system32\DRIVERS\msiscsi.sys ( \Driver\iScsiPrt [0x85533EB8] )
Signed
0x873AF00096.00 KbImage
C:\Windows\system32\DRIVERS\cdrom.sys ( \Driver\cdrom [0x854798F8] )
Signed
0x8BA2900032.00 KbImage
C:\Windows\system32\drivers\rdpencdd.sys ( \Driver\RDPENCDD [0x8576C478] )
Signed
0x8B00200040.00 KbImage
C:\Windows\system32\DRIVERS\mssmbios.sys ( \Driver\mssmbios [0x855012E8] )
Signed
0x95D1400048.00 KbImage
C:\Windows\System32\drivers\tcpipreg.sys ( \Driver\tcpipreg [0x8609D590] )
Signed
0x94834000168.00 KbImage
C:\Windows\system32\DRIVERS\nwifi.sys ( \Driver\NativeWifiP [0x85FEA030] )
Signed
0x8BACB000200.00 KbImage
C:\Windows\System32\DRIVERS\netbt.sys ( \Driver\netbt [0x856D34D0] )
Signed
0x875F400032.00 KbImage
C:\Windows\system32\DRIVERS\AtiPcie.sys ( \Driver\AtiPcie [0x847ABAD8] )
Signed
0x8759E00032.00 KbImage
C:\Windows\System32\Drivers\spldr.sys ( \Driver\spldr [0x847E2688] )
Signed
0x95CED00040.00 KbImage
C:\Windows\System32\Drivers\secdrv.SYS ( \Driver\secdrv [0x86102610] )
Signed
0x8BA6900080.00 KbImage
C:\Windows\system32\DRIVERS\smb.sys ( \Driver\Smb [0x8578F410] )
Signed
0x8B5C800092.00 KbImage
C:\Windows\system32\drivers\SBREdrv.sys ( \Driver\SBRE [0x85763478] )
Signed
0x81FD4000204.00 KbImage
C:\Windows\system32\hal.dll ( \Driver\ACPI_HAL [0x839561C8] )
Signed
0x81C1B0003.72 MbImage
C:\Windows\system32\ntkrnlpa.exe ( \Driver\WMIxWDM [0x839688D0] )
Signed
0x80423000260.00 KbImage
C:\Windows\system32\CLFS.SYS ( \Driver\CLFS [0x846F5450] )
Signed
0x8732500036.00 KbImage
C:\Windows\system32\drivers\crcdisk.sys ( \Driver\crcdisk [0x84E9E478] )
Signed
0x873EA00080.00 KbImage
C:\Windows\system32\DRIVERS\raspptp.sys ( \Driver\PptpMiniport [0x8547D030] )
Signed
0x8060000052.00 KbImage
C:\Windows\system32\DRIVERS\umbus.sys ( \Driver\umbus [0x854FDF38] )
Signed
0x8A6000007.16 MbImage
C:\Windows\system32\DRIVERS\atikmdag.sys ( \Driver\atikmdag [0x8545A198] )
Signed
0x8B12B00060.00 KbImage
C:\Windows\system32\DRIVERS\rimmptsk.sys ( \Driver\rimmptsk [0x854772C0] )
Signed
0x8754E00020.00 KbImage
C:\Windows\system32\DRIVERS\TVALZ_O.SYS ( \Driver\TVALZ [0x847FB6D8] )
Signed
0x8BB9000036.00 KbImage
C:\Windows\system32\DRIVERS\VBoxUSBMon.sys ( \Driver\VBoxUSBMon [0x859AB890] )
Signed
0x8B1DD00092.00 KbImage
C:\Windows\system32\DRIVERS\rasl2tp.sys ( \Driver\Rasl2tp [0x855336B0] )
Signed
0x823D600064.00 KbImage
C:\Windows\system32\DRIVERS\termdd.sys ( \Driver\TermDD [0x855003C8] )
Signed
0x8B56900052.00 KbImage
C:\Windows\system32\drivers\modem.sys ( \Driver\Modem [0x856F5478] )
Signed
0x8736100064.00 KbImage
C:\Windows\system32\DRIVERS\amdk8.sys ( \Driver\AmdK8 [0x8549C570] )
Signed
0x9487B000428.00 KbImage
C:\Windows\system32\drivers\HTTP.sys ( \Driver\HTTP [0x85A4AF38] )
Signed
0x8ADF000060.00 KbImage
C:\Windows\system32\DRIVERS\raspppoe.sys ( \Driver\RasPppoe [0x85531CC8] )
Signed
0x8BE4300092.00 KbImage
C:\Windows\system32\DRIVERS\usbccgp.sys ( \Driver\usbccgp [0x85884EC0] )
Signed
0x8BA2100032.00 KbImage
C:\Windows\System32\DRIVERS\RDPCDD.sys ( \Driver\RDPCDD [0x85772318] )
Signed
0x95DA9000116.00 KbImage
C:\Windows\system32\drivers\3qyhufha.sys ( \Driver\3qyhufha [0x840F1E50] )
VBA32 Signed
0x823C100084.00 KbImage
C:\Windows\system32\DRIVERS\rassstp.sys ( \Driver\RasSstp [0x8550E608] )
Signed
0x8B0000008.00 KbImage
C:\Windows\system32\DRIVERS\swenum.sys ( \Driver\swenum [0x85506D30] )
Signed
0x8B407000212.00 KbImage
C:\Windows\system32\DRIVERS\usbhub.sys ( \Driver\usbhub [0x85503F38] )
Signed
0x8BAC500024.00 KbImage
C:\Windows\System32\Drivers\CSN5PDTS82.sys ( \Driver\CSN5PDTS82 [0x8578F318] )
Signed
0x8734E00044.00 KbImage
C:\Windows\system32\DRIVERS\tunnel.sys ( \Driver\tunnel [0x8545BB08] )
Signed
0x8ADD300040.00 KbImage
C:\Windows\system32\DRIVERS\usbohci.sys ( \Driver\usbohci [0x8547E330] )
Signed
0x8BE7C00032.00 KbImage
C:\Windows\system32\DRIVERS\mouhid.sys ( \Driver\mouhid [0x85882808] )
Signed
0x912800002.01 MbImage
C:\Windows\System32\win32k.sys ( \Driver\Win32k [0x847147C0] )
Signed
0x8735900032.00 KbImage
C:\Windows\system32\DRIVERS\FwLnk.sys ( \Driver\FwLnk [0x85470D30] )
Signed
0x8BA4A00036.00 KbImage
C:\Windows\System32\DRIVERS\rasacd.sys ( \Driver\RasAcd [0x8576E3D0] )
Signed
0x8BAFD00088.00 KbImage
C:\Windows\system32\DRIVERS\pacer.sys ( \Driver\PSched [0x856D7108] )
Signed
0x823E6000104.00 KbImage
C:\Windows\system32\DRIVERS\VBoxNetFlt.sys ( \Driver\VBoxNetFlt [0x85506BB0] )
Signed
0x94803000132.00 KbImage
C:\Program Files\Sandboxie\SbieDrv.sys ( \Driver\SbieDrv [0x85FDC650] )
Signed
0x806B6000296.00 KbImage
C:\Windows\System32\drivers\volmgrx.sys ( \Driver\volmgrx [0x84715B28] )
Signed
0x95C0F000888.00 KbImage
C:\Windows\system32\drivers\peauth.sys ( \Driver\PEAUTH [0x860E3640] )
Signed
0x8072500032.00 KbImage
C:\Windows\system32\drivers\atapi.sys ( \Driver\atapi [0x847153F0] )
Signed
0x8B0F300064.00 KbImage
C:\Windows\system32\DRIVERS\ohci1394.sys ( \Driver\ohci1394 [0x8562BF38] )
Signed
0x8220000056.00 KbImage
C:\Windows\system32\DRIVERS\circlass.sys ( \Driver\circlass [0x85500118] )
Signed
0x8071500064.00 KbImage
C:\Windows\System32\drivers\mountmgr.sys ( \Driver\MountMgr [0x847156E0] )
Signed
0x875BC000156.00 KbImage
C:\Windows\System32\drivers\ecache.sys ( \Driver\Ecache [0x847FE8D8] )
Signed
0x8B5E600048.00 KbImage
C:\Windows\System32\drivers\vga.sys ( \Driver\VgaSave [0x8576D3A0] )
Signed
0x8B43C00068.00 KbImage
C:\Windows\System32\Drivers\NDProxy.SYS ( \Driver\NDProxy [0x856A3400] )
Signed
0x8065C00032.00 KbImage
C:\Windows\system32\drivers\msisadrv.sys ( \Driver\msisadrv [0x847148B8] )
Signed
0x8069A00012.00 KbImage
C:\Windows\system32\DRIVERS\compbatt.sys ( \Driver\Compbatt [0x84773F38] )
Signed
0x8BEF400060.00 KbImage
C:\Windows\system32\DRIVERS\monitor.sys ( \Driver\monitor [0x85D8B5C0] )
Signed
0x87553000300.00 KbImage
C:\Windows\system32\DRIVERS\tos_sps32.sys ( \Driver\tos_sps32 [0x848B6268] )
Signed
0x8B60B0001.85 MbImage
C:\Windows\system32\drivers\RTKVHDA.sys ( \Driver\IntcAzAudAddService [0x8571B318] )
Signed
0x8B0AE00044.00 KbImage
C:\Windows\system32\DRIVERS\kbdclass.sys ( \Driver\kbdclass [0x8553DF38] )
Signed
0x8B14E000324.00 KbImage
C:\Windows\system32\DRIVERS\rixdptsk.sys ( \Driver\rismxdp [0x854774D8] )
Signed
0x8B0E800044.00 KbImage
C:\Windows\system32\DRIVERS\mouclass.sys ( \Driver\mouclass [0x8546DD08] )
Signed
0x8078D000452.00 KbImage
C:\Windows\System32\Drivers\ksecdd.sys ( \Driver\KSecDD [0x846F6C58] )
Signed
0x8220F0001.04 MbImage
C:\Windows\system32\drivers\ndis.sys ( \Driver\NDIS [0x846F7D50] )
Signed
0x8B7F400028.00 KbImage
C:\Windows\System32\Drivers\Beep.SYS ( \Driver\Beep [0x8573E478] )
Signed
0x8BF03000108.00 KbImage
C:\Windows\system32\drivers\luafv.sys ( \FileSystem\luafv [0x85EBA518] )
Signed
0x8077D00064.00 KbImage
C:\Windows\system32\drivers\fileinfo.sys ( \FileSystem\FileInfo [0x846F4458] )
Signed
0x9498400096.00 KbImage
C:\Windows\system32\DRIVERS\mrxsmb20.sys ( \FileSystem\mrxsmb20 [0x860CE448] )
Signed
0x8074B000200.00 KbImage
C:\Windows\system32\drivers\fltmgr.sys ( \FileSystem\FltMgr [0x839A6DD8] )
Signed
0x95D9300088.00 KbImage
C:\Windows\system32\DRIVERS\cdfs.sys ( \FileSystem\cdfs [0x86389570] )
Signed
0x9494B000228.00 KbImage
C:\Windows\system32\DRIVERS\mrxsmb10.sys ( \FileSystem\mrxsmb10 [0x860D8BE8] )
Signed
0x8B7E400036.00 KbImage
C:\Windows\System32\Drivers\Fs_Rec.SYS ( \FileSystem\Fs_Rec [0x85744478] )
Signed
0x8BA3C00056.00 KbImage
C:\Windows\System32\Drivers\Npfs.SYS ( \FileSystem\Npfs [0x858045C0] )
Signed
0x81C1B0003.72 MbImage
C:\Windows\system32\ntkrnlpa.exe ( \FileSystem\RAW [0x846D1990] )
Signed
0x875AD00060.00 KbImage
C:\Windows\System32\Drivers\mup.sys ( \FileSystem\Mup [0x847F4648] )
Signed
0x95D20000156.00 KbImage
C:\Windows\System32\DRIVERS\srv2.sys ( \FileSystem\srv2 [0x86144F00] )
Signed
0x8BE0900092.00 KbImage
C:\Windows\System32\Drivers\dfsc.sys ( \FileSystem\DfsC [0x857A6DE8] )
Signed
0x95D47000304.00 KbImage
C:\Windows\System32\DRIVERS\srv.sys ( \FileSystem\srv [0x86144030] )
Signed
0x8BF1E00068.00 KbImage
C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys ( \FileSystem\a2acc [0x85ECEF38] )
Signed
0x9492C000124.00 KbImage
C:\Windows\system32\DRIVERS\mrxsmb.sys ( \FileSystem\mrxsmb [0x860B4E90] )
Signed
0x8BA3100044.00 KbImage
C:\Windows\System32\Drivers\Msfs.SYS ( \FileSystem\Msfs [0x85775478] )
Signed
0x94913000100.00 KbImage
C:\Windows\system32\DRIVERS\bowser.sys ( \FileSystem\bowser [0x847B1900] )
Signed
0x8BBBB000240.00 KbImage
C:\Windows\system32\DRIVERS\rdbss.sys ( \FileSystem\rdbss [0x859EBF38] )
Signed
0x8BB6F00056.00 KbImage
C:\Windows\system32\DRIVERS\netbios.sys ( \FileSystem\NetBIOS [0x857E7980] )
Signed
0x874050001.06 MbImage
C:\Windows\System32\Drivers\Ntfs.sys ( \FileSystem\Ntfs [0x84865F38] )
Signed
0x95CF7000116.00 KbImage
C:\Windows\System32\DRIVERS\srvnet.sys ( \FileSystem\srvnet [0x86105C80] )
Signed
0x8040300028.00 KbImage
C:\Windows\system32\kdcom.dll
Signed
0x8040A00068.00 KbImage
C:\Windows\system32\PSHED.dll
Signed
0x8041B00032.00 KbImage
C:\Windows\system32\BOOTVID.dll
Signed
0x80464000896.00 KbImage
C:\Windows\system32\CI.dll
Signed
0x805C000052.00 KbImage
C:\Windows\system32\drivers\WDFLDR.SYS
Signed
0x8065300036.00 KbImage
C:\Windows\system32\drivers\WMILIB.SYS
Signed
0x8069D00040.00 KbImage
C:\Windows\system32\DRIVERS\BATTC.SYS
Signed
0x8070700056.00 KbImage
C:\Windows\system32\drivers\PCIIDEX.SYS
Signed
0x8072D000120.00 KbImage
C:\Windows\system32\drivers\ataport.SYS
Signed
0x8231A000172.00 KbImage
C:\Windows\system32\drivers\msrpc.sys
Signed
0x82345000236.00 KbImage
C:\Windows\system32\drivers\NETIO.SYS
Signed
0x872E9000108.00 KbImage
C:\Windows\System32\drivers\fwpkclnt.sys
Signed
0x87304000132.00 KbImage
C:\Windows\system32\drivers\CLASSPNP.SYS
Signed
0x8ADC700048.00 KbImage
C:\Windows\System32\drivers\watchdog.sys
Signed
0x87371000248.00 KbImage
C:\Windows\system32\DRIVERS\USBPORT.SYS
Signed
0x8B0E60008.00 KbImage
C:\Windows\system32\DRIVERS\USBD.SYS
Signed
0x8B10300056.00 KbImage
C:\Windows\system32\DRIVERS\1394BUS.SYS
Signed
0x82380000260.00 KbImage
C:\Windows\system32\DRIVERS\storport.sys
Signed
0x8B1D200044.00 KbImage
C:\Windows\system32\DRIVERS\TDI.SYS
Signed
0x805CD000168.00 KbImage
C:\Windows\system32\DRIVERS\ks.sys
Signed
0x8B576000180.00 KbImage
C:\Windows\system32\drivers\portcls.sys
Signed
0x8B5A3000148.00 KbImage
C:\Windows\system32\drivers\drmk.sys
Signed
0x8B5DF00028.00 KbImage
C:\Windows\system32\DRIVERS\HIDPARSE.SYS
Signed
0x8BA00000132.00 KbImage
C:\Windows\System32\drivers\VIDEOPRT.SYS
Signed
0x8BE6300064.00 KbImage
C:\Windows\system32\DRIVERS\HIDCLASS.SYS
Signed
0x8BECA00052.00 KbImage
C:\Windows\System32\Drivers\crashdmp.sys
Signed
0x8BED700044.00 KbImageC:\Windows\System32\Drivers\dump_dumpata.sysFile doesn't exist
0x8BEE200032.00 KbImageC:\Windows\System32\Drivers\dump_atapi.sysFile doesn't exist
0x8BEEA00040.00 KbImage
C:\Windows\System32\drivers\Dxapi.sys
Signed
0x914A000036.00 KbImage
C:\Windows\System32\TSDDD.dll
Signed
0x914C000056.00 KbImage
C:\Windows\System32\cdd.dll
Signed
0x8BF37000704.00 KbImage
C:\Windows\system32\drivers\spsys.sys
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
svchost.exe ( PID : 328 ) - 25 Modules
0x0002000056.00 KbImage
C:\Windows\System32\HPZinw12.dll
0x001200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003800003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x00E500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 448 ) - 48 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003800003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x007000002.00 KbData
C:\Windows\System32\msxml3r.dll
Signed
0x00A400003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x716B00001.15 MbImage
C:\Windows\System32\msxml3.dll
Signed
0x71D30000160.00 KbImage
C:\Windows\System32\fundisc.dll
Signed
0x72650000452.00 KbImage
C:\Windows\System32\wiaservc.dll
Signed
0x728E000036.00 KbImage
C:\Windows\System32\wsdchngr.dll
Signed
0x729E000028.00 KbImage
C:\Windows\System32\wiatrace.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x750C0000532.00 KbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754F0000220.00 KbImage
C:\Windows\System32\msv1_0.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75A1000068.00 KbImage
C:\Windows\System32\cryptdll.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
smss.exe ( PID : 456 ) - 2 Modules
0x47DE000072.00 KbImage
C:\Windows\System32\smss.exe
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
svchost.exe ( PID : 480 ) - 24 Modules
0x0002000064.00 KbImage
C:\Windows\System32\HPZipm12.dll
0x001100002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x002200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 492 ) - 44 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003B00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x72770000364.00 KbImage
C:\Windows\System32\IPSECSVC.DLL
Signed
0x72C6000040.00 KbImage
C:\Windows\System32\FwRemoteSvr.dll
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
ReflectService.exe ( PID : 504 ) - 33 Modules
0x001A00002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x00400000236.00 KbImage
C:\Program Files\Macrium\Reflect\ReflectService.exe
Signed
0x004400003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x67D70000208.00 KbImage
C:\Windows\System32\mstask.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SnareCore.exe ( PID : 512 ) - 34 Modules
0x00400000304.00 KbImage
C:\Program Files\Snare\SnareCore.exe
0x004500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x7275000072.00 KbImage
C:\Windows\System32\pnrpnsp.dll
Signed
0x7298000024.00 KbImage
C:\Windows\System32\rasadhlp.dll
Signed
0x729C000032.00 KbImage
C:\Windows\System32\winrnr.dll
Signed
0x729D000060.00 KbImage
C:\Windows\System32\NapiNSP.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
csrss.exe ( PID : 524 ) - 33 Modules
0x002100002.50 KbDataC:\Windows\System32\en-US\csrss.exe.muiHandle opened
0x002300007.11 KbData
C:\Windows\Fonts\vgasys.fon
Signed
0x0025000026.05 KbData
C:\Windows\Fonts\marlett.ttf
Signed
0x004100003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x007A00005.05 KbData
C:\Windows\Fonts\vgaoem.fon
Signed
0x007B000035.80 KbData
C:\Windows\Fonts\dosapp.fon
Signed
0x007C00006.19 KbData
C:\Windows\Fonts\cga40woa.fon
Signed
0x008100004.20 KbData
C:\Windows\Fonts\cga80woa.fon
Signed
0x008200008.17 KbData
C:\Windows\Fonts\ega40woa.fon
Signed
0x0083000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x008E00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x01400000499.31 KbData
C:\Windows\Fonts\segoeui.ttf
Signed
0x01650000660.02 KbData
C:\Windows\Fonts\tahoma.ttf
Signed
0x017000007.45 MbData
C:\Windows\Fonts\meiryo.ttc
Signed
0x01E800008.74 MbData
C:\Windows\Fonts\msgothic.ttc
Signed
0x0274000014.03 MbData
C:\Windows\Fonts\msjh.ttf
Signed
0x0355000014.35 MbData
C:\Windows\Fonts\msyh.ttf
Signed
0x043B00004.14 MbData
C:\Windows\Fonts\malgun.ttf
Signed
0x055F0000634.36 KbData
C:\Windows\Fonts\micross.ttf
Signed
0x4A3C000020.00 KbImage
C:\Windows\System32\csrss.exe
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75DD0000384.00 KbImage
C:\Windows\System32\winsrv.dll
Signed
0x75E3000076.00 KbImage
C:\Windows\System32\basesrv.dll
Signed
0x75E5000060.00 KbImage
C:\Windows\System32\csrsrv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
wininit.exe ( PID : 580 ) - 28 Modules
0x0015000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x003E0000104.00 KbImage
C:\Windows\System32\wininit.exe
Signed
0x004000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
csrss.exe ( PID : 592 ) - 35 Modules
0x002700007.11 KbData
C:\Windows\Fonts\vgasys.fon
Signed
0x002B000026.05 KbData
C:\Windows\Fonts\marlett.ttf
Signed
0x005C00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00D20000499.31 KbData
C:\Windows\Fonts\segoeui.ttf
Signed
0x01430000610.03 KbData
C:\Windows\Fonts\tahomabd.ttf
Signed
0x014E0000634.36 KbData
C:\Windows\Fonts\micross.ttf
Signed
0x0158000081.78 KbData
C:\Windows\Fonts\wingding.ttf
Signed
0x01640000748.69 KbData
C:\Windows\Fonts\arial.ttf
Signed
0x01700000808.74 KbData
C:\Windows\Fonts\times.ttf
Signed
0x017D000063.14 KbData
C:\Windows\Fonts\sserife.fon
Signed
0x017E0000480.33 KbData
C:\Windows\Fonts\segoeuib.ttf
Signed
0x01860000370.82 KbData
C:\Windows\Fonts\segoeuii.ttf
Signed
0x018C0000149.29 KbData
C:\Windows\Fonts\verdanab.ttf
Signed
0x018F0000181.35 KbData
C:\Windows\Fonts\verdana.ttf
Signed
0x01920000816.28 KbData
C:\Windows\Fonts\timesbd.ttf
Signed
0x01BF0000660.02 KbData
C:\Windows\Fonts\tahoma.ttf
Signed
0x01CA00007.45 MbData
C:\Windows\Fonts\meiryo.ttc
Signed
0x024200008.74 MbData
C:\Windows\Fonts\msgothic.ttc
Signed
0x02CE000014.03 MbData
C:\Windows\Fonts\msjh.ttf
Signed
0x03AF000014.35 MbData
C:\Windows\Fonts\msyh.ttf
Signed
0x049500004.14 MbData
C:\Windows\Fonts\malgun.ttf
Signed
0x4A3C000020.00 KbImage
C:\Windows\System32\csrss.exe
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75DD0000384.00 KbImage
C:\Windows\System32\winsrv.dll
Signed
0x75E3000076.00 KbImage
C:\Windows\System32\basesrv.dll
Signed
0x75E5000060.00 KbImage
C:\Windows\System32\csrsrv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
services.exe ( PID : 624 ) - 34 Modules
0x002300003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E90000284.00 KbImage
C:\Windows\System32\services.exe
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75CE0000312.00 KbImage
C:\Windows\System32\scesrv.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D6000060.00 KbImage
C:\Windows\System32\ncobjapi.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
lsass.exe ( PID : 640 ) - 68 Modules
0x003900003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x0091000064.53 KbData
C:\Windows\System32\C_28591.NLS
Signed
0x00AF00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00F0000024.00 KbImage
C:\Windows\System32\lsass.exe
Signed
0x6A640000152.00 KbImage
C:\Windows\System32\dssenh.dll
Signed
0x7157000052.00 KbImage
C:\Windows\System32\psbase.dll
Signed
0x715A000036.00 KbImage
C:\Windows\System32\pstorsvc.dll
Signed
0x73BE000032.00 KbImage
C:\Windows\System32\keyiso.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75260000184.00 KbImage
C:\Windows\System32\scecli.dll
Signed
0x75290000176.00 KbImage
C:\Windows\System32\wdigest.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x75330000860.00 KbImage
C:\Windows\System32\winbrand.dll
Signed
0x75410000592.00 KbImage
C:\Windows\System32\netlogon.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x754F0000220.00 KbImage
C:\Windows\System32\msv1_0.dll
Signed
0x75530000500.00 KbImage
C:\Windows\System32\kerberos.dll
Signed
0x755B000072.00 KbImage
C:\Windows\System32\TSpkg.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x755F00008.00 KbImage
C:\Windows\System32\msprivs.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x756A0000120.00 KbImage
C:\Windows\System32\shimeng.dll
Signed
0x756C000064.00 KbImage
C:\Windows\AppPatch\EMET.dll
Signed
0x756D000024.00 KbImage
C:\Windows\System32\cngaudit.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x7596000068.00 KbImage
C:\Windows\System32\feclient.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75A1000068.00 KbImage
C:\Windows\System32\cryptdll.dll
Signed
0x75A30000492.00 KbImage
C:\Windows\System32\samsrv.dll
Signed
0x75AB00001.21 MbImage
C:\Windows\System32\lsasrv.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75CD000028.00 KbImage
C:\Windows\System32\sysntfy.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
lsm.exe ( PID : 652 ) - 33 Modules
0x003900003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00F30000236.00 KbImage
C:\Windows\System32\lsm.exe
Signed
0x00F700003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7595000024.00 KbImage
C:\Windows\System32\wmsgapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75CD000028.00 KbImage
C:\Windows\System32\sysntfy.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
winlogon.exe ( PID : 680 ) - 32 Modules
0x0011000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x00500000320.00 KbImage
C:\Windows\System32\winlogon.exe
Signed
0x005500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x73AB0000716.00 KbImage
C:\Windows\System32\WindowsCodecs.dll
Signed
0x73C90000248.00 KbImage
C:\Windows\System32\shsvcs.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 836 ) - 42 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003C00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x74CA0000552.00 KbImage
C:\Windows\System32\rpcss.dll
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75150000228.00 KbImage
C:\Windows\System32\umpnpmgr.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
a2service.exe ( PID : 880 ) - 59 Modules
0x0027000064.53 KbData
C:\Windows\System32\C_1251.NLS
Signed
0x002A000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x003E00006.00 KbDataC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_5.82.6001.18000_en-us_9e72cfd97d4d7bf2\comctl32.dll.muiHandle opened
0x003F00004.50 KbDataC:\Windows\System32\en-US\userenv.dll.muiHandle opened
0x004000002.91 MbImage
C:\Program Files\Emsisoft Anti-Malware\a2service.exe
Signed
0x006F00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00C0000011.50 KbDataC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_en-us_72e6f33f34dfabb9\comctl32.dll.muiHandle opened
0x00C1000011.00 KbDataC:\Windows\System32\en-US\wsock32.dll.muiHandle opened
0x00C200009.00 KbDataC:\Windows\System32\en-US\ws2_32.dll.muiHandle opened
0x00C3000011.00 KbDataC:\Windows\System32\en-US\mswsock.dll.muiHandle opened
0x00C600007.00 KbDataC:\Windows\System32\en-US\fltlib.dll.muiHandle opened
0x00D20000232.00 KbImage
C:\Program Files\Emsisoft Anti-Malware\a2wsc.dll
Signed
0x00DD00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x033000002.82 MbImage
C:\Program Files\Emsisoft Anti-Malware\a2update.dll
Signed
0x04E600002.45 MbImage
C:\Program Files\Emsisoft Anti-Malware\engine.dll
Signed
0x65BF00006.77 MbImage
C:\Program Files\Emsisoft Anti-Malware\t3.dll
Signed
0x7158000032.00 KbImage
C:\Windows\System32\wscisvif.dll
Signed
0x744E000044.00 KbImage
C:\Windows\System32\wscapi.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F10000132.00 KbImage
C:\Program Files\Emsisoft Anti-Malware\a2acc.dll
Signed
0x74FE0000132.00 KbImage
C:\Program Files\Emsisoft Anti-Malware\a2dix86.dll
Signed
0x7501000072.00 KbImage
C:\Program Files\Emsisoft Anti-Malware\a2core32.dll
Signed
0x7504000028.00 KbImage
C:\Windows\System32\fltLib.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x750C0000532.00 KbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755E000020.00 KbImage
C:\Windows\System32\msimg32.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 988 ) - 36 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x002200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x00E500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x74CA0000552.00 KbImage
C:\Windows\System32\rpcss.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1024 ) - 55 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x005100003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x73E80000436.00 KbImage
C:\Windows\System32\tdh.dll
Signed
0x73EF00003.32 MbImage
C:\ProgramData\Microsoft\Windows Defender\Definition Updates\Default\MpEngine.dll
Signed
0x743E000060.00 KbImage
C:\Program Files\Windows Defender\MpRtPlug.dll
Signed
0x744D000028.00 KbImage
C:\Windows\System32\ktmw32.dll
Signed
0x744E000044.00 KbImage
C:\Windows\System32\wscapi.dll
Signed
0x74C00000268.00 KbImage
C:\Program Files\Windows Defender\MpSvc.dll
Signed
0x74C50000308.00 KbImage
C:\Program Files\Windows Defender\MpClient.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
TNaviSrv.exe ( PID : 1088 ) - 21 Modules
0x0040000076.00 KbImage
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe
0x004200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x725400001.06 MbImage
C:\Windows\winsxs\x86_microsoft.vc80.mfc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_cbf21254470d8752\mfc80u.dll
0x728F000056.00 KbImage
C:\Windows\winsxs\x86_microsoft.vc80.mfcloc_1fc8b3b9a1e18e3b_8.0.50727.4053_none_03ca5532205cb096\mfc80ENU.dll
0x729F0000620.00 KbImage
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
Ati2evxx.exe ( PID : 1124 ) - 29 Modules
0x00400000620.00 KbImage
C:\Windows\System32\Ati2evxx.exe
Signed
0x004A00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1144 ) - 82 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003800003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00720000200.00 KbImage
C:\Windows\System32\drivers\fltMgr.sys
Signed Hidden in memory
0x007A000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x008E00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x01600000320.00 KbImage
C:\Windows\System32\winlogon.exe
Signed Hidden in memory
0x28B10000896.00 KbImage
C:\Windows\System32\ci.dll
Signed Hidden in memory
0x4B8C000068.00 KbImage
C:\Windows\System32\PSHED.DLL
Signed Hidden in memory
0x666200001.63 MbImage
C:\Windows\System32\wuaueng.dll
Signed Hidden in memory
0x667D00001.75 MbImage
C:\Windows\System32\qmgr.dll
Signed Hidden in memory
0x69250000532.00 KbImage
C:\Windows\System32\wuapi.dll
Signed
0x69320000880.00 KbImage
C:\Windows\System32\dbghelp.dll
Signed
0x695B000072.00 KbImage
C:\Windows\System32\wscsvc.dll
Signed
0x6976000064.00 KbImage
C:\Windows\System32\tbssvc.dll
Signed Hidden in memory
0x6A670000612.00 KbImage
C:\Windows\System32\wbem\fastprox.dll
Signed
0x6BD7000012.00 KbImage
C:\Windows\System32\wbem\WinMgmtR.dll
Signed Resource Dll
0x6BF9000064.00 KbImage
C:\Windows\System32\wbem\wbemsvc.dll
Signed
0x6BFA000044.00 KbImage
C:\Windows\System32\wbem\wbemprox.dll
Signed
0x71650000364.00 KbImage
C:\Windows\System32\wbemcomn.dll
Signed
0x727D00001.04 MbImage
C:\Windows\System32\diagperf.dll
Signed Hidden in memory
0x72BA0000564.00 KbImage
C:\Windows\System32\emdmgmt.dll
Signed Hidden in memory
0x72E50000140.00 KbImage
C:\Windows\System32\dps.dll
Signed Hidden in memory
0x731C0000592.00 KbImage
C:\Windows\System32\schedsvc.dll
Signed Hidden in memory
0x73520000520.00 KbImage
C:\Windows\System32\wlansvc.dll
Signed Hidden in memory
0x736C0000192.00 KbImage
C:\Windows\System32\WUDFPlatform.dll
Signed Hidden in memory
0x73CD0000408.00 KbImage
C:\Windows\System32\AudioEng.dll
Signed
0x73D40000132.00 KbImage
C:\Windows\System32\AudioSes.dll
Signed
0x73D70000164.00 KbImage
C:\Windows\System32\profsvc.dll
Signed Hidden in memory
0x73DE0000572.00 KbImage
C:\Windows\System32\gpsvc.dll
Signed Hidden in memory
0x74310000608.00 KbImage
C:\Windows\System32\adtschema.dll
Signed Resource Dll
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x74470000324.00 KbImage
C:\Windows\System32\audiosrv.dll
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x745B00001008.00 KbImage
C:\Windows\System32\wevtsvc.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x750C0000532.00 KbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed Hidden in memory
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1168 ) - 102 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x002900003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E000002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x00E100002.00 KbData
C:\Windows\System32\msxml6r.dll
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x6AE800003.04 MbImage
C:\Windows\System32\netshell.dll
Signed
0x6C590000104.00 KbImage
C:\Windows\System32\mprapi.dll
Signed
0x6C5B0000824.00 KbImage
C:\Windows\System32\rasdlg.dll
Signed
0x7156000040.00 KbImage
C:\Windows\System32\pcadm.dll
Signed
0x71610000248.00 KbImage
C:\Windows\System32\PortableDeviceApi.dll
Signed
0x71820000280.00 KbImage
C:\Windows\System32\netman.dll
Signed
0x718A000084.00 KbImage
C:\Windows\System32\wpdbusenum.dll
Signed
0x71CA0000552.00 KbImage
C:\Windows\System32\sysmain.dll
Signed
0x71D60000184.00 KbImage
C:\Windows\System32\credui.dll
Signed
0x72500000204.00 KbImage
C:\Windows\System32\adsldpc.dll
Signed
0x72710000212.00 KbImage
C:\Windows\System32\activeds.dll
Signed
0x72BA0000564.00 KbImage
C:\Windows\System32\emdmgmt.dll
Signed
0x72C3000052.00 KbImage
C:\Windows\System32\pcasvc.dll
Signed
0x72C5000036.00 KbImage
C:\Windows\System32\hidserv.dll
Signed
0x72C80000228.00 KbImage
C:\Windows\System32\wdscore.dll
Signed
0x72FE000084.00 KbImage
C:\Windows\System32\wdi.dll
Signed
0x73010000384.00 KbImage
C:\Windows\System32\netcfgx.dll
Signed
0x730700001.29 MbImage
C:\Windows\System32\msxml6.dll
Signed
0x7331000024.00 KbImage
C:\Windows\System32\wlanutil.dll
Signed
0x7332000096.00 KbImage
C:\Windows\System32\wlgpclnt.dll
Signed
0x733400001.48 MbImage
C:\Windows\System32\onex.dll
Signed
0x734C0000328.00 KbImage
C:\Windows\System32\wlansec.dll
Signed
0x73520000520.00 KbImage
C:\Windows\System32\wlansvc.dll
Signed
0x735B000064.00 KbImage
C:\Windows\System32\l2gpstore.dll
Signed
0x735C0000144.00 KbImage
C:\Windows\System32\eappcfg.dll
Signed
0x735F0000304.00 KbImage
C:\Windows\System32\wlanmsm.dll
Signed
0x7369000056.00 KbImage
C:\Windows\System32\eappprxy.dll
Signed
0x736C0000192.00 KbImage
C:\Windows\System32\WUDFPlatform.dll
Signed
0x73BC000064.00 KbImage
C:\Windows\System32\WUDFSvc.dll
Signed
0x73BD000044.00 KbImage
C:\Windows\System32\uxsms.dll
Signed
0x73C0000036.00 KbImage
C:\Windows\System32\hid.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x74470000324.00 KbImage
C:\Windows\System32\audiosrv.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x74860000124.00 KbImage
C:\Windows\System32\WinSCard.dll
Signed
0x7488000048.00 KbImage
C:\Windows\System32\rtutils.dll
Signed
0x74890000196.00 KbImage
C:\Windows\System32\tapi32.dll
Signed
0x748D0000296.00 KbImage
C:\Windows\System32\rasapi32.dll
Signed
0x749E0000192.00 KbImage
C:\Windows\System32\duser.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x74F4000080.00 KbImage
C:\Windows\System32\rasman.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x75530000500.00 KbImage
C:\Windows\System32\kerberos.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75A1000068.00 KbImage
C:\Windows\System32\cryptdll.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75CD000028.00 KbImage
C:\Windows\System32\sysntfy.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1216 ) - 122 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x002F00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x008B00002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x00A000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x666200001.63 MbImage
C:\Windows\System32\wuaueng.dll
Signed
0x667D00001.75 MbImage
C:\Windows\System32\qmgr.dll
Signed
0x67CB000064.00 KbImage
C:\Windows\System32\wbem\NCProv.dll
Signed
0x68C800001.41 MbImage
C:\Windows\System32\esent.dll
Signed
0x69400000204.00 KbImage
C:\Windows\System32\upnp.dll
Signed
0x696D0000500.00 KbImage
C:\Windows\System32\wbem\WmiPrvSD.dll
Signed
0x69770000348.00 KbImage
C:\Windows\System32\wbem\wbemess.dll
Signed
0x6A670000612.00 KbImage
C:\Windows\System32\wbem\fastprox.dll
Signed
0x6AC50000272.00 KbImage
C:\Windows\System32\wbem\repdrvfs.dll
Signed
0x6ACA0000740.00 KbImage
C:\Windows\System32\wbem\wbemcore.dll
Signed
0x6ADB000048.00 KbImage
C:\Windows\System32\mspatcha.dll
Signed
0x6ADC000044.00 KbImage
C:\Windows\System32\bitsigd.dll
Signed
0x6ADD0000268.00 KbImage
C:\Windows\System32\wbem\esscli.dll
Signed
0x6BEB000092.00 KbImage
C:\Windows\System32\wbem\wmiutils.dll
Signed
0x6BF9000064.00 KbImage
C:\Windows\System32\wbem\wbemsvc.dll
Signed
0x6BFA000044.00 KbImage
C:\Windows\System32\wbem\wbemprox.dll
Signed
0x6C52000032.00 KbImage
C:\Windows\System32\bitsperf.dll
Signed
0x7154000036.00 KbImage
C:\Windows\System32\TSChannel.dll
Signed
0x7159000032.00 KbImage
C:\Windows\System32\npmproxy.dll
Signed
0x715B0000380.00 KbImage
C:\Windows\System32\winhttp.dll
Signed
0x71650000364.00 KbImage
C:\Windows\System32\wbemcomn.dll
Signed
0x71C70000168.00 KbImage
C:\Windows\System32\wbem\WMIsvc.dll
Signed
0x7290000048.00 KbImage
C:\Windows\System32\ssdpapi.dll
Signed
0x72910000444.00 KbImage
C:\Windows\System32\IKEEXT.DLL
Signed
0x72AF000032.00 KbImage
C:\Windows\System32\seclogon.dll
Signed
0x72CC00001.04 MbImage
C:\Windows\System32\vssapi.dll
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x72FB000020.00 KbImage
C:\Windows\System32\shfolder.dll
Signed
0x72FC000080.00 KbImage
C:\Windows\System32\vsstrace.dll
Signed
0x7300000036.00 KbImage
C:\Windows\System32\aelupsvc.dll
Signed
0x731C0000592.00 KbImage
C:\Windows\System32\schedsvc.dll
Signed
0x73260000272.00 KbImage
C:\Windows\System32\taskcomp.dll
Signed
0x732C000044.00 KbImage
C:\Windows\System32\wiarpc.dll
Signed
0x7364000060.00 KbImage
C:\Windows\System32\umb.dll
Signed
0x73650000192.00 KbImage
C:\Windows\System32\eapphost.dll
Signed
0x7368000064.00 KbImage
C:\Windows\System32\eapsvc.dll
Signed
0x73BF000056.00 KbImage
C:\Windows\System32\Sens.dll
Signed
0x73C90000248.00 KbImage
C:\Windows\System32\shsvcs.dll
Signed
0x73D70000164.00 KbImage
C:\Windows\System32\profsvc.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x73DE0000572.00 KbImage
C:\Windows\System32\gpsvc.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x7441000068.00 KbImage
C:\Windows\System32\mmcss.dll
Signed
0x7446000044.00 KbImage
C:\Windows\System32\appinfo.dll
Signed
0x744D000028.00 KbImage
C:\Windows\System32\ktmw32.dll
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x7488000048.00 KbImage
C:\Windows\System32\rtutils.dll
Signed
0x74890000196.00 KbImage
C:\Windows\System32\tapi32.dll
Signed
0x748D0000296.00 KbImage
C:\Windows\System32\rasapi32.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x74F4000080.00 KbImage
C:\Windows\System32\rasman.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x750C0000532.00 KbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x7595000024.00 KbImage
C:\Windows\System32\wmsgapi.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75CD000028.00 KbImage
C:\Windows\System32\sysntfy.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D6000060.00 KbImage
C:\Windows\System32\ncobjapi.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
audiodg.exe ( PID : 1304 ) - 44 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\audiodg.exe.muiHandle opened
0x004300003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00AA0000108.00 KbImage
C:\Windows\System32\audiodg.exe
Signed
0x00AC00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x736F0000216.00 KbImage
C:\Windows\System32\mfplat.dll
Signed
0x737300001.46 MbImage
C:\Windows\System32\WMALFXGFXDSP.dll
Signed
0x738B00002.00 MbImage
C:\Windows\System32\RtkAPO.dll
Signed
0x73C10000292.00 KbImage
C:\Windows\System32\AUDIOKSE.dll
Signed
0x73CD0000408.00 KbImage
C:\Windows\System32\AudioEng.dll
Signed
0x73D40000132.00 KbImage
C:\Windows\System32\AudioSes.dll
Signed
0x73E7000016.00 KbImage
C:\Windows\System32\ksuser.dll
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
TODDSrv.exe ( PID : 1356 ) - 24 Modules
0x00400000120.00 KbImage
C:\Windows\System32\TODDSrv.exe
0x004200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SLsvc.exe ( PID : 1364 ) - 24 Modules
0x003000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E600003.26 MbImage
C:\Windows\System32\SLsvc.exe
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1428 ) - 76 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x002C00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x008700002.00 KbData
C:\Windows\System32\msxml3r.dll
Signed
0x009400003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x69110000160.00 KbImage
C:\Windows\System32\ssdpsrv.dll
Signed
0x691A000072.00 KbImage
C:\Windows\System32\fdSSDP.dll
Signed
0x691C000072.00 KbImage
C:\Windows\System32\fdWSD.dll
Signed
0x6920000024.00 KbImage
C:\Windows\System32\fdPHost.dll
Signed
0x6921000040.00 KbImage
C:\Windows\System32\fdProxy.dll
Signed
0x6CC10000192.00 KbImage
C:\Windows\System32\mlang.dll
Signed
0x6F6B0000356.00 KbImage
C:\Windows\System32\WSDApi.dll
Signed
0x7159000032.00 KbImage
C:\Windows\System32\npmproxy.dll
Signed
0x715B0000380.00 KbImage
C:\Windows\System32\winhttp.dll
Signed
0x716B00001.15 MbImage
C:\Windows\System32\msxml3.dll
Signed
0x717E0000240.00 KbImage
C:\Windows\System32\netprofm.dll
Signed
0x718C0000288.00 KbImage
C:\Windows\System32\w32time.dll
Signed
0x71D30000160.00 KbImage
C:\Windows\System32\fundisc.dll
Signed
0x7290000048.00 KbImage
C:\Windows\System32\ssdpapi.dll
Signed
0x72990000148.00 KbImage
C:\Windows\System32\sstpsvc.dll
Signed
0x72B0000044.00 KbImage
C:\Windows\System32\httpapi.dll
Signed
0x72C4000032.00 KbImage
C:\Windows\System32\nsisvc.dll
Signed
0x73B70000280.00 KbImage
C:\Windows\System32\es.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x7488000048.00 KbImage
C:\Windows\System32\rtutils.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75A1000068.00 KbImage
C:\Windows\System32\cryptdll.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
TosBtSrv.exe ( PID : 1492 ) - 25 Modules
0x00400000124.00 KbImage
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
Signed
0x006F00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
Ati2evxx.exe ( PID : 1520 ) - 36 Modules
0x0017000064.00 KbImage
C:\Windows\System32\ati2edxx.dll
Signed
0x00190000240.00 KbImage
C:\Windows\System32\Ati2evxx.dll
Signed
0x00400000620.00 KbImage
C:\Windows\System32\Ati2evxx.exe
Signed
0x004A00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x10000000260.00 KbImage
C:\Windows\System32\atipdlxx.dll
Signed
0x73B70000280.00 KbImage
C:\Windows\System32\es.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SbieSvc.exe ( PID : 1528 ) - 36 Modules
0x002B00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x0100000072.00 KbImage
C:\Program Files\Sandboxie\SbieSvc.exe
Signed
0x7330000052.00 KbImage
C:\Windows\System32\pstorec.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
0x7D220000252.00 KbImage
C:\Program Files\Sandboxie\SbieDll.dll
Signed
pfsvc.exe ( PID : 1640 ) - 40 Modules
0x00400000360.00 KbImage
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exe
Signed Handle opened
0x004600003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x7158000032.00 KbImage
C:\Windows\System32\wscisvif.dll
Signed
0x736A0000112.00 KbImage
C:\Windows\System32\oledlg.dll
Signed
0x744E000044.00 KbImage
C:\Windows\System32\wscapi.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
spoolsv.exe ( PID : 1768 ) - 94 Modules
0x000A0000132.00 KbImage
C:\Windows\System32\spoolsv.exe
Signed
0x003600002.00 KbData
C:\Windows\System32\msxml6r.dll
Signed
0x004900003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00B300003.00 KbDataC:\Windows\System32\en-US\usbmon.dll.muiHandle opened
0x00B900002.00 KbData
C:\Windows\System32\msxml3r.dll
Signed
0x00C50000184.00 KbImage
C:\Windows\System32\TBTMon.dll
0x018F00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x01D70000116.00 KbImage
C:\Windows\System32\TosBtHcrpAPI.dll
0x01DB0000104.00 KbImage
C:\Windows\System32\TosBdAPI.dll
0x01DE000096.00 KbImage
C:\Windows\System32\tbtmon98Language.dll
0x029D0000388.00 KbImage
C:\Windows\System32\TosBtAPI.dll
0x6E9C0000132.00 KbImage
C:\Windows\System32\inetpp.dll
Signed
0x6EA1000052.00 KbImage
C:\Windows\System32\printcom.dll
Signed
0x6EA20000328.00 KbImage
C:\Windows\System32\spool\prtprocs\w32x86\hpfpp083.dll
0x6F63000024.00 KbImage
C:\Windows\System32\SensApi.dll
Signed
0x6F640000444.00 KbImage
C:\Windows\System32\win32spl.dll
Signed
0x6F6B0000356.00 KbImage
C:\Windows\System32\WSDApi.dll
Signed
0x6F710000180.00 KbImage
C:\Windows\System32\WSDMon.dll
Signed
0x6F9A000024.00 KbImage
C:\Windows\System32\WlS0WndH.dll
Signed
0x6F9F000044.00 KbImage
C:\Windows\System32\usbmon.dll
Signed
0x6FD1000032.00 KbImage
C:\Windows\System32\mgmtapi.dll
Signed
0x6FD2000040.00 KbImage
C:\Windows\System32\tcpmib.dll
Signed
0x6FF0000028.00 KbImage
C:\Windows\System32\netrap.dll
Signed
0x7011000060.00 KbImage
C:\Windows\System32\wsnmp32.dll
Signed
0x70120000144.00 KbImage
C:\Windows\System32\tcpmon.dll
Signed
0x701B0000136.00 KbImage
C:\Windows\System32\hpf3l083.dll
0x71490000616.00 KbImage
C:\Windows\System32\localspl.dll
Signed
0x7155000036.00 KbImage
C:\Windows\System32\snmpapi.dll
Signed
0x715B0000380.00 KbImage
C:\Windows\System32\winhttp.dll
Signed
0x716B00001.15 MbImage
C:\Windows\System32\msxml3.dll
Signed
0x71D30000160.00 KbImage
C:\Windows\System32\fundisc.dll
Signed
0x71D9000020.00 KbImage
C:\Windows\System32\sfc.dll
Signed
0x7275000072.00 KbImage
C:\Windows\System32\pnrpnsp.dll
Signed
0x7298000024.00 KbImage
C:\Windows\System32\rasadhlp.dll
Signed
0x729C000032.00 KbImage
C:\Windows\System32\winrnr.dll
Signed
0x729D000060.00 KbImage
C:\Windows\System32\NapiNSP.dll
Signed
0x72B0000044.00 KbImage
C:\Windows\System32\httpapi.dll
Signed
0x730700001.29 MbImage
C:\Windows\System32\msxml6.dll
Signed
0x732D0000168.00 KbImage
C:\Windows\System32\spoolss.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x755D000020.00 KbImage
C:\Windows\System32\wship6.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x756A0000120.00 KbImage
C:\Windows\System32\shimeng.dll
Signed
0x756C000064.00 KbImage
C:\Windows\AppPatch\EMET.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1796 ) - 59 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x003600003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x7159000032.00 KbImage
C:\Windows\System32\npmproxy.dll
Signed
0x727D00001.04 MbImage
C:\Windows\System32\diagperf.dll
Signed
0x72A90000360.00 KbImage
C:\Windows\System32\taskschd.dll
Signed
0x72DD0000408.00 KbImage
C:\Windows\System32\MPSSVC.dll
Signed
0x72E4000024.00 KbImage
C:\Windows\System32\pnpts.dll
Signed
0x72E50000140.00 KbImage
C:\Windows\System32\dps.dll
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x72F50000340.00 KbImage
C:\Windows\System32\BFE.DLL
Signed
0x72FE000084.00 KbImage
C:\Windows\System32\wdi.dll
Signed
0x732B000032.00 KbImage
C:\Windows\System32\wfapigp.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x744D000028.00 KbImage
C:\Windows\System32\ktmw32.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
ULCDRSvr.exe ( PID : 1856 ) - 6 Modules
0x0040000056.00 KbImage
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
0x004100003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
agrsmsvc.exe ( PID : 1940 ) - 18 Modules
0x001F00002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x003000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x0100000052.00 KbImage
C:\Windows\System32\agrsmsvc.exe
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1956 ) - 72 Modules
0x000200002.50 KbDataC:\Windows\System32\en-US\svchost.exe.muiHandle opened
0x004400003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00BC000064.00 KbDataC:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdbHandle opened
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x0159000064.00 KbDataC:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdbHandle opened
0x016D000064.00 KbDataC:\Windows\System32\catroot2\{127D0A1D-4EF2-11D1-8608-00C04FC295EE}\catdbHandle opened
0x016E000064.00 KbDataC:\Windows\System32\catroot2\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\catdbHandle opened
0x68C800001.41 MbImage
C:\Windows\System32\esent.dll
Signed
0x69510000356.00 KbImage
C:\Windows\System32\msdtckrm.dll
Signed
0x6AD60000184.00 KbImage
C:\Windows\System32\clusapi.dll
Signed
0x715B0000380.00 KbImage
C:\Windows\System32\winhttp.dll
Signed
0x71870000172.00 KbImage
C:\Windows\System32\nlasvc.dll
Signed
0x71D60000184.00 KbImage
C:\Windows\System32\credui.dll
Signed
0x71DA0000104.00 KbImage
C:\Windows\System32\ncsi.dll
Signed
0x72500000204.00 KbImage
C:\Windows\System32\adsldpc.dll
Signed
0x72710000212.00 KbImage
C:\Windows\System32\activeds.dll
Signed
0x7290000048.00 KbImage
C:\Windows\System32\ssdpapi.dll
Signed
0x72CC00001.04 MbImage
C:\Windows\System32\vssapi.dll
Signed
0x72E80000136.00 KbImage
C:\Windows\System32\cryptsvc.dll
Signed
0x72FC000080.00 KbImage
C:\Windows\System32\vsstrace.dll
Signed
0x73B70000280.00 KbImage
C:\Windows\System32\es.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x744D000028.00 KbImage
C:\Windows\System32\ktmw32.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752E0000272.00 KbImage
C:\Windows\System32\schannel.dll
Signed
0x7560000028.00 KbImage
C:\Windows\System32\credssp.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75A1000068.00 KbImage
C:\Windows\System32\cryptdll.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D7000088.00 KbImage
C:\Windows\System32\authz.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
svchost.exe ( PID : 1968 ) - 10 Modules
0x002D00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00E4000032.00 KbImage
C:\Windows\System32\svchost.exe
Signed
0x71C40000140.00 KbImage
C:\Windows\System32\wersvc.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
PresentationFontCache.exe ( PID : 1980 ) - 34 Modules
0x0004000048.00 KbImage
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Signed
0x003300003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x008F00008.63 KbData
C:\Windows\System32\l_intl.nls
Signed
0x0092000019.84 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpHandle opened
0x00B60000256.00 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpHandle opened
0x00C100003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x6EA8000011.67 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\4e2a5be87816c8fcd3ae72cc9530d3ef\PresentationCore.ni.dll
0x701E00007.52 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\34942db56010e4225825bfae8a27559f\System.ni.dll
0x7097000010.97 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3aac7b97549d4ccf0c7dca3d1777f9b4\mscorlib.ni.dll
0x719100003.17 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\93391bd2f02e492718c69bef3abc5a64\WindowsBase.ni.dll
0x71DC00001.67 MbImage
C:\Windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
Signed
0x71F700005.56 MbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Signed
0x729F0000620.00 KbImage
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll
Signed
0x72B10000220.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\35f20a6b69d5c7033b4b1873456e5074\System.ServiceProcess.ni.dll
0x72B50000280.00 KbImage
C:\Windows\System32\mscoree.dll
Signed
0x72C7000064.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFontCac#\532c2b963925149aec2a7c6279fe0168\PresentationFontCache.ni.exe
0x72FB000020.00 KbImage
C:\Windows\System32\shfolder.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
taskeng.exe ( PID : 2228 ) - 25 Modules
0x00210000172.00 KbImage
C:\Windows\System32\taskeng.exe
Signed
0x004500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x7154000036.00 KbImage
C:\Windows\System32\TSChannel.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
taskeng.exe ( PID : 2460 ) - 68 Modules
0x001D00002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x00210000172.00 KbImage
C:\Windows\System32\taskeng.exe
Signed
0x0035000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x004600003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x025F0000260.00 KbImage
C:\Windows\System32\atipdlxx.dll
Signed
0x10000000172.00 KbImage
C:\Windows\System32\atitmmxx.dll
Signed
0x6CC40000184.00 KbImage
C:\Windows\System32\QAGENT.DLL
Signed
0x6D2B000092.00 KbImage
C:\Windows\System32\QUTIL.DLL
Signed
0x6E1900001.25 MbImage
C:\Windows\System32\TMM.dll
Signed
0x6FD3000024.00 KbImage
C:\Windows\System32\d3d8thk.dll
Signed
0x6FD400001.73 MbImage
C:\Windows\System32\d3d9.dll
Signed
0x70170000172.00 KbImage
C:\Windows\System32\msutb.dll
Signed
0x701A000032.00 KbImage
C:\Windows\System32\MsCtfMonitor.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x7148000028.00 KbImage
C:\Windows\System32\PlaySndSrv.dll
Signed
0x7153000032.00 KbImage
C:\Windows\System32\HotStartUserAgent.dll
Signed
0x7154000036.00 KbImage
C:\Windows\System32\TSChannel.dll
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x73C6000028.00 KbImage
C:\Windows\System32\midimap.dll
Signed
0x73C7000080.00 KbImage
C:\Windows\System32\msacm32.dll
Signed
0x73CD0000408.00 KbImage
C:\Windows\System32\AudioEng.dll
Signed
0x73D40000132.00 KbImage
C:\Windows\System32\AudioSes.dll
Signed
0x73DA000036.00 KbImage
C:\Windows\System32\msacm32.drv
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73E7000016.00 KbImage
C:\Windows\System32\ksuser.dll
Signed
0x743B0000188.00 KbImage
C:\Windows\System32\wdmaud.drv
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
dwm.exe ( PID : 2508 ) - 34 Modules
0x003B00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00DA000096.00 KbImage
C:\Windows\System32\dwm.exe
Signed
0x024900003.74 MbImage
C:\Windows\System32\atiumdva.dll
Signed
0x029500001.20 MbData
C:\Windows\Resources\Themes\Aero\aero.msstyles
Signed
0x6F9B0000212.00 KbImage
C:\Windows\System32\uDWM.dll
Signed
0x6FA000003.04 MbImage
C:\Windows\System32\atiumdag.dll
Signed
0x6FD3000024.00 KbImage
C:\Windows\System32\d3d8thk.dll
Signed
0x6FD400001.73 MbImage
C:\Windows\System32\d3d9.dll
Signed
0x6FF100001.94 MbImage
C:\Windows\System32\milcore.dll
Signed
0x7015000096.00 KbImage
C:\Windows\System32\dwmredir.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x73AB0000716.00 KbImage
C:\Windows\System32\WindowsCodecs.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
explorer.exe ( PID : 2612 ) - 153 Modules
0x003000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x008700002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x009800002.00 KbData
C:\Windows\System32\msxml3r.dll
Signed
0x00A500002.80 MbImage
C:\Windows\explorer.exe
Signed
0x019200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x028B000011.50 KbDataC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_en-us_72e6f33f34dfabb9\comctl32.dll.muiHandle opened
0x02DF000012.00 KbDataC:\Windows\System32\en-US\imageres.dll.muiHandle opened
0x037D000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x037F000016.00 KbDataC:\Users\Punymicro\AppData\Roaming\Microsoft\Windows\Cookies\index.datHandle opened
0x0380000032.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.datHandle opened
0x0383000016.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\History\History.IE5\index.datHandle opened
0x03EF000015.09 MbData
C:\Windows\System32\imageres.dll
Signed
0x056A0000240.00 KbImage
C:\Program Files\Emsisoft Anti-Malware\a2contmenu.dll
Signed
0x1000000080.00 KbImage
C:\Program Files\7-Zip\7-zip.dll
0x61300000428.00 KbImage
C:\Program Files\Mythicsoft\Agent Ransack\ShellExt.dll
Signed
0x65B80000316.00 KbImage
C:\Program Files\Notepad++\NppShell_04.dll
0x66B5000015.09 MbImage
C:\Windows\System32\imageres.dll
Signed Resource Dll
0x67A70000384.00 KbImage
C:\Program Files\Common Files\microsoft shared\ink\tiptsf.dll
Signed
0x67C00000184.00 KbImage
C:\Windows\System32\syncui.dll
Signed
0x67C30000348.00 KbImage
C:\Windows\System32\zipfldr.dll
Signed
0x67C9000088.00 KbImage
C:\Program Files\Windows Defender\MpOAV.dll
Signed
0x67CC000024.00 KbImage
C:\Windows\System32\dciman32.dll
Signed
0x67CD000092.00 KbImage
C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
Signed
0x67D1000088.00 KbImage
C:\Windows\System32\synceng.dll
Signed
0x67D3000088.00 KbImage
C:\Windows\System32\thumbcache.dll
Signed
0x68BD0000652.00 KbImage
C:\Windows\System32\bthprops.cpl
Signed
0x6921000040.00 KbImage
C:\Windows\System32\fdProxy.dll
Signed
0x698D00002.11 MbImage
C:\Windows\System32\SyncCenter.dll
Signed
0x6AE20000384.00 KbImage
C:\Windows\System32\imapi2.dll
Signed
0x6AE800003.04 MbImage
C:\Windows\System32\netshell.dll
Signed
0x6BDE0000240.00 KbImage
C:\Windows\System32\webcheck.dll
Signed
0x6BE20000228.00 KbImage
C:\Windows\System32\wscntfy.dll
Signed
0x6BE60000308.00 KbImage
C:\Windows\System32\srchadmin.dll
Signed
0x6BED0000172.00 KbImage
C:\Windows\System32\PortableDeviceTypes.dll
Signed
0x6BF60000140.00 KbImage
C:\Windows\System32\WPDShServiceObj.dll
Signed
0x6BFC00001.75 MbImage
C:\Windows\System32\pnidui.dll
Signed
0x6C50000052.00 KbImage
C:\Windows\System32\AltTab.dll
Signed
0x6C56000072.00 KbImage
C:\Windows\System32\wlanapi.dll
Signed
0x6C680000728.00 KbImage
C:\Windows\System32\batmeter.dll
Signed
0x6C740000584.00 KbImage
C:\Windows\System32\stobject.dll
Signed
0x6C850000132.00 KbImage
C:\Windows\ehome\ehSSO.dll
Signed
0x6CB00000192.00 KbImage
C:\Windows\System32\SndVolSSO.dll
Signed
0x6CC40000184.00 KbImage
C:\Windows\System32\QAGENT.DLL
Signed
0x6D2B000092.00 KbImage
C:\Windows\System32\QUTIL.DLL
Signed
0x6D4800005.81 MbImage
C:\Windows\System32\ieframe.dll
Signed
0x6DA500002.53 MbImage
C:\Windows\System32\NlsLexicons0009.dll
Signed
0x6DCE00004.66 MbImage
C:\Windows\System32\NlsData0009.dll
Signed
0x6E4100002.15 MbImage
C:\Windows\System32\msi.dll
Signed
0x6E640000796.00 KbImage
C:\Windows\System32\NaturalLanguage6.dll
Signed
0x6E71000036.00 KbImage
C:\Windows\System32\ExplorerFrame.dll
Signed
0x6E790000296.00 KbImage
C:\Windows\System32\ntshrui.dll
Signed
0x6E7E0000240.00 KbImage
C:\Windows\System32\msshsq.dll
Signed
0x6E820000332.00 KbImage
C:\Windows\System32\actxprxy.dll
Signed
0x6E89000044.00 KbImage
C:\Windows\System32\cscapi.dll
Signed
0x6E8C000028.00 KbImage
C:\Windows\System32\msiltcfg.dll
Signed
0x6E8E0000712.00 KbImage
C:\Windows\System32\timedate.cpl
Signed
0x6E9A000024.00 KbImage
C:\Windows\System32\IconCodecService.dll
Signed
0x6E9B000036.00 KbImage
C:\Windows\System32\linkinfo.dll
Signed
0x6E9F0000124.00 KbImage
C:\Windows\System32\EhStorShell.dll
Signed
0x6F7400001.27 MbImage
C:\Windows\System32\browseui.dll
Signed
0x6F8900001.03 MbImage
C:\Windows\System32\shdocvw.dll
Signed
0x70170000172.00 KbImage
C:\Windows\System32\msutb.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x7159000032.00 KbImage
C:\Windows\System32\npmproxy.dll
Signed
0x715B0000380.00 KbImage
C:\Windows\System32\winhttp.dll
Signed
0x71610000248.00 KbImage
C:\Windows\System32\PortableDeviceApi.dll
Signed
0x716B00001.15 MbImage
C:\Windows\System32\msxml3.dll
Signed
0x71D30000160.00 KbImage
C:\Windows\System32\fundisc.dll
Signed
0x72EB0000600.00 KbImage
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x7331000024.00 KbImage
C:\Windows\System32\wlanutil.dll
Signed
0x733400001.48 MbImage
C:\Windows\System32\onex.dll
Signed
0x735C0000144.00 KbImage
C:\Windows\System32\eappcfg.dll
Signed
0x7369000056.00 KbImage
C:\Windows\System32\eappprxy.dll
Signed
0x73AB0000716.00 KbImage
C:\Windows\System32\WindowsCodecs.dll
Signed
0x73B70000280.00 KbImage
C:\Windows\System32\es.dll
Signed
0x73C0000036.00 KbImage
C:\Windows\System32\hid.dll
Signed
0x73C6000028.00 KbImage
C:\Windows\System32\midimap.dll
Signed
0x73C7000080.00 KbImage
C:\Windows\System32\msacm32.dll
Signed
0x73CD0000408.00 KbImage
C:\Windows\System32\AudioEng.dll
Signed
0x73D40000132.00 KbImage
C:\Windows\System32\AudioSes.dll
Signed
0x73DA000036.00 KbImage
C:\Windows\System32\msacm32.drv
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x73E7000016.00 KbImage
C:\Windows\System32\ksuser.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x743B0000188.00 KbImage
C:\Windows\System32\wdmaud.drv
Signed
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x7443000088.00 KbImage
C:\Windows\System32\shacct.dll
Signed
0x744E000044.00 KbImage
C:\Windows\System32\wscapi.dll
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x74980000188.00 KbImage
C:\Windows\System32\xmllite.dll
Signed
0x749E0000192.00 KbImage
C:\Windows\System32\duser.dll
Signed
0x74A100001.91 MbImage
C:\Windows\System32\authui.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x75330000860.00 KbImage
C:\Windows\System32\winbrand.dll
Signed
0x755E000020.00 KbImage
C:\Windows\System32\msimg32.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757B0000256.00 KbImage
C:\Windows\System32\wevtapi.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
RtHDVCpl.exe ( PID : 2760 ) - 49 Modules
0x002300002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x004000004.50 MbImage
C:\Windows\RtHDVCpl.exe
Signed
0x008800003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x6E720000448.00 KbImage
C:\Windows\System32\dsound.dll
Signed
0x736A0000112.00 KbImage
C:\Windows\System32\oledlg.dll
Signed
0x736F0000216.00 KbImage
C:\Windows\System32\mfplat.dll
Signed
0x73CD0000408.00 KbImage
C:\Windows\System32\AudioEng.dll
Signed
0x73D40000132.00 KbImage
C:\Windows\System32\AudioSes.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x744F000028.00 KbImage
C:\Windows\System32\avrt.dll
Signed
0x74500000160.00 KbImage
C:\Windows\System32\MMDevAPI.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75240000104.00 KbImage
C:\Windows\System32\powrprof.dll
Signed
0x755E000020.00 KbImage
C:\Windows\System32\msimg32.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SynTPStart.exe ( PID : 2780 ) - 25 Modules
0x00400000104.00 KbImage
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
Signed
0x004200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7593000080.00 KbImage
C:\Windows\System32\mpr.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
AntiLogger.exe ( PID : 2824 ) - 76 Modules
0x002D000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x0031000032.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.datHandle opened
0x0032000032.00 KbDataC:\Users\Punymicro\AppData\Roaming\Microsoft\Windows\Cookies\index.datHandle opened
0x0033000016.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\History\History.IE5\index.datHandle opened
0x0034000011.50 KbDataC:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_en-us_72e6f33f34dfabb9\comctl32.dll.muiHandle opened
0x004000008.97 MbImage
C:\Program Files\AntiLogger\AntiLogger.exe
Signed
0x00D000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x027D000012.00 KbDataC:\Windows\System32\en-US\imageres.dll.muiHandle opened
0x03E6000064.53 KbData
C:\Windows\System32\C_1254.NLS
Signed
0x0406000015.09 MbData
C:\Windows\System32\imageres.dll
Signed
0x6CB60000464.00 KbImage
C:\Windows\System32\riched20.dll
Signed
0x6CBE000024.00 KbImage
C:\Windows\System32\riched32.dll
Signed
0x6E88000052.00 KbImage
C:\Windows\System32\sfc_os.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x71D9000020.00 KbImage
C:\Windows\System32\sfc.dll
Signed
0x7275000072.00 KbImage
C:\Windows\System32\pnrpnsp.dll
Signed
0x7298000024.00 KbImage
C:\Windows\System32\rasadhlp.dll
Signed
0x729C000032.00 KbImage
C:\Windows\System32\winrnr.dll
Signed
0x729D000060.00 KbImage
C:\Windows\System32\NapiNSP.dll
Signed
0x73DD000060.00 KbImage
C:\Windows\System32\nlaapi.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x7496000096.00 KbImage
C:\Windows\System32\olepro32.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x74F6000020.00 KbImage
C:\Windows\System32\WSHTCPIP.DLL
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x754B0000236.00 KbImage
C:\Windows\System32\mswsock.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x756A0000120.00 KbImage
C:\Windows\System32\shimeng.dll
Signed
0x756C000064.00 KbImage
C:\Windows\AppPatch\EMET.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
PFGUI.exe ( PID : 2832 ) - 123 Modules
0x004000003.95 MbImage
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exe
Signed
0x008000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00EF00002.00 KbData
C:\Windows\System32\netmsg.dll
Signed
0x01B500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x01FD000048.00 KbDataC:\Windows\System32\en-US\odbcji32.dll.muiHandle opened
0x01FF000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x02010000196.00 KbDataC:\Windows\System32\en-US\netmsg.dll.muiHandle opened
0x0208000048.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.datHandle opened
0x0209000032.00 KbDataC:\Users\Punymicro\AppData\Roaming\Microsoft\Windows\Cookies\index.datHandle opened
0x020A000032.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\History\History.IE5\index.datHandle opened
0x021C00002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x023E0000100.00 KbDataC:\Windows\System32\ieframe.dllHandle opened
0x0240000016.00 KbDataC:\Windows\System32\stdole2.tlbHandle opened
0x0241000044.00 KbDataC:\Windows\System32\en-US\fwpuclnt.dll.muiHandle opened
0x024200003.50 KbDataC:\Windows\System32\en-US\azroles.dll.muiHandle opened
0x0245000036.00 KbDataC:\Windows\System32\en-US\dfsr.exe.muiHandle opened
0x0246000044.00 KbDataC:\Windows\System32\en-US\fwpuclnt.dll.muiHandle opened
0x035A0000224.50 KbData
C:\Windows\System32\lsm.exe
Signed
0x035E000030.00 KbData
C:\Windows\System32\httpapi.dll
Signed
0x035F000055.00 KbData
C:\Windows\System32\tbssvc.dll
Signed
0x08BD0000584.00 KbData
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x08C70000100.00 KbDataC:\Windows\System32\expsrv.dllHandle opened
0x08D10000584.00 KbData
C:\Windows\System32\FWPUCLNT.DLL
Signed
0x091C0000739.50 KbData
C:\Windows\System32\azroles.dll
Signed
0x092800002.00 MbData
C:\Windows\System32\dfsr.exe
Signed
0x09480000579.00 KbData
C:\Windows\System32\netlogon.dll
Signed
0x0F9A000044.00 KbImage
C:\Windows\System32\vbajet32.dll
Signed
0x0F9C0000392.00 KbImage
C:\Windows\System32\expsrv.dll
Signed Handle opened
0x67BA0000288.00 KbImage
C:\Windows\System32\msjtes40.dll
Signed
0x68A2000060.00 KbImage
C:\Windows\System32\wbem\WmiPerfInst.dll
Signed
0x69010000476.00 KbImage
C:\Windows\System32\mshtmled.dll
Signed
0x692E000044.00 KbImage
C:\Windows\System32\perfproc.dll
Signed
0x695D0000500.00 KbImage
C:\Windows\System32\jscript.dll
Signed
0x69690000248.00 KbImage
C:\Windows\System32\pdh.dll
Signed
0x6A670000612.00 KbImage
C:\Windows\System32\wbem\fastprox.dll
Signed
0x6BEB000092.00 KbImage
C:\Windows\System32\wbem\wmiutils.dll
Signed
0x6BF9000064.00 KbImage
C:\Windows\System32\wbem\wbemsvc.dll
Signed
0x6BFA000044.00 KbImage
C:\Windows\System32\wbem\wbemprox.dll
Signed
0x6BFB000044.00 KbImage
C:\Windows\System32\msimtf.dll
Signed
0x6C1800003.45 MbImage
C:\Windows\System32\mshtml.dll
Signed
0x6CC10000192.00 KbImage
C:\Windows\System32\mlang.dll
Signed
0x6CC70000608.00 KbImage
C:\Windows\System32\mswstr10.dll
Signed
0x6CD100001.52 MbImage
C:\Windows\System32\msjet40.dll
Signed
0x6CEA00001.18 MbImage
C:\Windows\System32\comsvcs.dll
Signed
0x6D040000312.00 KbImage
C:\Windows\System32\odbcjt32.dll
Signed
0x6D090000440.00 KbImage
C:\Program Files\Common Files\System\Ole DB\msdasql.dll
Signed
0x6D100000676.00 KbImage
C:\Program Files\Common Files\System\Ole DB\oledb32.dll
Signed
0x6D1B0000692.00 KbImage
C:\Program Files\Common Files\System\ado\msado15.dll
Signed
0x6D260000164.00 KbImage
C:\Windows\System32\msls31.dll
Signed
0x6D29000068.00 KbImage
C:\Windows\System32\msjter40.dll
Signed
0x6D2D000024.00 KbImage
C:\Windows\System32\odbcji32.dll
Signed
0x6D2E000060.00 KbImage
C:\Program Files\Common Files\System\Ole DB\msdasqlr.dll
Signed
0x6D2F000092.00 KbImage
C:\Program Files\Common Files\System\Ole DB\oledb32r.dll
Signed
0x6D310000504.00 KbImage
C:\Windows\System32\capicom.dll
Signed
0x6D3A0000100.00 KbImage
C:\Program Files\Common Files\System\Ole DB\msdatl3.dll
Signed
0x6D3C0000224.00 KbImage
C:\Windows\System32\odbcint.dll
Signed
0x6D40000024.00 KbImage
C:\Windows\System32\msjint40.dll
Signed
0x6D410000404.00 KbImage
C:\Windows\System32\odbc32.dll
Signed
0x6D4800005.81 MbImage
C:\Windows\System32\ieframe.dll
Signed Handle opened
0x6E2D0000124.00 KbImage
C:\Windows\System32\msdart.dll
Signed
0x6E8D000048.00 KbImage
C:\Windows\System32\mssign32.dll
Signed
0x71650000364.00 KbImage
C:\Windows\System32\wbemcomn.dll
Signed
0x736A0000112.00 KbImage
C:\Windows\System32\oledlg.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x7488000048.00 KbImage
C:\Windows\System32\rtutils.dll
Signed
0x74890000196.00 KbImage
C:\Windows\System32\tapi32.dll
Signed
0x748D0000296.00 KbImage
C:\Windows\System32\rasapi32.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x74F4000080.00 KbImage
C:\Windows\System32\rasman.dll
Signed
0x74F70000408.00 KbImage
C:\Windows\System32\FirewallAPI.dll
Signed
0x7506000028.00 KbImage
C:\Windows\System32\wsock32.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x75190000180.00 KbImage
C:\Windows\System32\wintrust.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x756E0000136.00 KbImage
C:\Windows\System32\dhcpcsvc6.dll
Signed
0x7571000028.00 KbImage
C:\Windows\System32\winnsi.dll
Signed
0x75750000212.00 KbImage
C:\Windows\System32\dhcpcsvc.dll
Signed
0x75790000100.00 KbImage
C:\Windows\System32\IPHLPAPI.DLL
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77200000164.00 KbImage
C:\Windows\System32\imagehlp.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
jusched.exe ( PID : 2840 ) - 25 Modules
0x00400000260.00 KbImage
C:\Program Files\Common Files\Java\Java Update\jusched.exe
Signed
0x004500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x756A0000120.00 KbImage
C:\Windows\System32\shimeng.dll
Signed
0x756C000064.00 KbImage
C:\Windows\AppPatch\EMET.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
TOSCDSPD.exe ( PID : 2856 ) - 18 Modules
0x000200002.50 KbDataC:\Program Files\Toshiba\TOSCDSPD\en-us\toscdspd.exe.muiHandle opened
0x00400000428.00 KbImage
C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe
0x004700003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SbieCtrl.exe ( PID : 2872 ) - 34 Modules
0x001B00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00D1000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x01000000400.00 KbImage
C:\Program Files\Sandboxie\SbieCtrl.exe
Signed
0x028000001.88 MbImage
C:\Program Files\Sandboxie\SbieMsg.dll
Signed
0x6D3C0000224.00 KbImage
C:\Windows\System32\odbcint.dll
Signed
0x6D410000404.00 KbImage
C:\Windows\System32\odbc32.dll
Signed
0x6E2F00001.12 MbImage
C:\Windows\System32\mfc42u.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
0x7D220000252.00 KbImage
C:\Program Files\Sandboxie\SbieDll.dll
Signed
MOM.exe ( PID : 3004 ) - 61 Modules
0x003000008.63 KbData
C:\Windows\System32\l_intl.nls
Signed
0x004500003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x009D0000112.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2764.39730__90ba9c70f846762e\MOM.Implementation.DLL
Hidden in memory Handle opened
0x00B0000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2729.30174__90ba9c70f846762e\LOG.Foundation.DLL
Hidden in memory Handle opened
0x00B200003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00F5000019.84 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpHandle opened
0x00F60000256.00 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpHandle opened
0x00FB000056.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
0x03BC000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2729.30188__90ba9c70f846762e\LOG.Foundation.Private.DLL
Hidden in memory Handle opened
0x03BD000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2764.39729__90ba9c70f846762e\LOG.Foundation.Implementation.DLL
Hidden in memory Handle opened
0x03BF000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2729.30207__90ba9c70f846762e\MOM.Foundation.DLL
Hidden in memory Handle opened
0x03C2000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2729.30211__90ba9c70f846762e\LOG.Foundation.Implementation.Private.DLL
Hidden in memory Handle opened
0x03CB000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2764.39436__90ba9c70f846762e\AEM.Server.DLL
Hidden in memory Handle opened
0x03CC000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2729.30184__90ba9c70f846762e\NEWAEM.Foundation.DLL
Hidden in memory Handle opened
0x69AF000011.26 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\27b0a88bfa56a9390f516b0fa55f3dcb\System.Web.ni.dll
0x6B19000011.87 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\b0be4ac8da47fbf783dabd1505e6c55e\System.Windows.Forms.ni.dll
0x6C83000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2764.39436__90ba9c70f846762e\AEM.Server.DLL
Handle opened
0x6C880000772.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e515919524c6be56f55ad12fbdd23c19\System.Runtime.Remoting.ni.dll
0x6C9500001.53 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\07e39e61fd6133a92333a2c98f2ffeb7\System.Drawing.ni.dll
0x6CC0000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2729.30184__90ba9c70f846762e\NEWAEM.Foundation.DLL
Handle opened
0x6CFE0000364.00 KbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
Signed
0x6D39000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2729.30211__90ba9c70f846762e\LOG.Foundation.Implementation.Private.DLL
Handle opened
0x701E00007.52 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\34942db56010e4225825bfae8a27559f\System.ni.dll
0x7097000010.97 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3aac7b97549d4ccf0c7dca3d1777f9b4\mscorlib.ni.dll
0x71F700005.56 MbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Signed
0x729F0000620.00 KbImage
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll
Signed
0x72B50000280.00 KbImage
C:\Windows\System32\mscoree.dll
Signed
0x72FB000020.00 KbImage
C:\Windows\System32\shfolder.dll
Signed
0x74250000748.00 KbImage
C:\Windows\System32\propsys.dll
Signed
0x7492000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2729.30207__90ba9c70f846762e\MOM.Foundation.DLL
Handle opened
0x7493000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2764.39729__90ba9c70f846762e\LOG.Foundation.Implementation.DLL
Handle opened
0x7495000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2729.30188__90ba9c70f846762e\LOG.Foundation.Private.DLL
Handle opened
0x749B000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2729.30174__90ba9c70f846762e\LOG.Foundation.DLL
Handle opened
0x749C0000112.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2764.39730__90ba9c70f846762e\MOM.Implementation.DLL
Handle opened
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SynTPEnh.exe ( PID : 3264 ) - 31 Modules
0x001600002.00 KbData
C:\Windows\System32\oleaccrc.dll
Signed
0x004000001008.00 KbImage
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
Signed
0x005000003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x10000000160.00 KbImage
C:\Windows\System32\SynCOM.dll
Signed
0x63010000152.00 KbImage
C:\Windows\System32\SynTPAPI.dll
Signed
0x74530000228.00 KbImage
C:\Windows\System32\oleacc.dll
Signed
0x74570000200.00 KbImage
C:\Windows\System32\winmm.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x750C0000532.00 KbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.6001.18000_none_886786f450a74a05\comctl32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75720000148.00 KbImage
C:\Windows\System32\winsta.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
CCC.exe ( PID : 3276 ) - 260 Modules
0x003400008.63 KbData
C:\Windows\System32\l_intl.nls
Signed
0x004800003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x009C000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2764.39730__90ba9c70f846762e\CCC.Implementation.DLL
Hidden in memory Handle opened
0x009E000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2729.30174__90ba9c70f846762e\LOG.Foundation.DLL
Hidden in memory Handle opened
0x00A0000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2729.30207__90ba9c70f846762e\MOM.Foundation.DLL
Hidden in memory Handle opened
0x00A1000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2729.30178__90ba9c70f846762e\CLI.Foundation.DLL
Hidden in memory Handle opened
0x00A2000056.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
0x016300003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x019B000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2729.30211__90ba9c70f846762e\LOG.Foundation.Implementation.Private.DLL
Hidden in memory Handle opened
0x019C000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2764.39729__90ba9c70f846762e\LOG.Foundation.Implementation.DLL
Hidden in memory Handle opened
0x019F000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2729.30188__90ba9c70f846762e\LOG.Foundation.Private.DLL
Hidden in memory Handle opened
0x01A0000019.84 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sorttbls.nlpHandle opened
0x01B40000112.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2764.39730__90ba9c70f846762e\MOM.Implementation.DLL
Hidden in memory Handle opened
0x03B7000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2729.30313__90ba9c70f846762e\CLI.Foundation.XManifest.DLL
Hidden in memory Handle opened
0x03B8000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2764.39438__90ba9c70f846762e\CLI.Component.Runtime.DLL
Hidden in memory Handle opened
0x03D50000256.00 KbDataC:\Windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\sortkey.nlpHandle opened
0x03DA000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2729.30209__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.DLL
Hidden in memory Handle opened
0x03DB000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2729.30193__90ba9c70f846762e\CLI.Foundation.Private.DLL
Hidden in memory Handle opened
0x03DC000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2729.30203__90ba9c70f846762e\CLI.Component.Runtime.Shared.DLL
Hidden in memory Handle opened
0x03DD000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.DLL
Hidden in memory Handle opened
0x03EA000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2764.39436__90ba9c70f846762e\AEM.Server.DLL
Hidden in memory Handle opened
0x03FD000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2729.30184__90ba9c70f846762e\NEWAEM.Foundation.DLL
Hidden in memory Handle opened
0x03FE000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2764.39436__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.DLL
Hidden in memory Handle opened
0x03FF000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2729.30176__90ba9c70f846762e\AEM.Foundation.DLL
Hidden in memory Handle opened
0x0460000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2729.30212__90ba9c70f846762e\AEM.Plugin.EEU.Shared.DLL
Hidden in memory Handle opened
0x0461000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2729.30201__90ba9c70f846762e\AEM.Server.Shared.DLL
Hidden in memory Handle opened
0x0462000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2764.39776__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.DLL
Hidden in memory Handle opened
0x0474000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2729.30222__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.DLL
Hidden in memory Handle opened
0x0475000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2729.30202__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.DLL
Hidden in memory Handle opened
0x0476000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.DLL
Hidden in memory Handle opened
0x0478000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.DLL
Hidden in memory Handle opened
0x0479000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2729.30256__90ba9c70f846762e\DEM.Graphics.DLL
Hidden in memory Handle opened
0x048A0000352.00 KbImage
C:\Windows\System32\ATIDEMGX.dll
Signed Hidden in memory Handle opened
0x04900000376.00 KbImage
C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
Signed Hidden in memory Handle opened
0x04DB000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2729.30199__90ba9c70f846762e\CLI.Caste.Graphics.Shared.DLL
Hidden in memory Handle opened
0x04DC000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.DLL
Hidden in memory Handle opened
0x04DD000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2729.30259__90ba9c70f846762e\DEM.OS.I0602.DLL
Hidden in memory Handle opened
0x04EE0000248.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2764.39446__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x04F3000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2729.30197__90ba9c70f846762e\AEM.Actions.CCAA.Shared.DLL
Hidden in memory Handle opened
0x0504000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2729.30242__90ba9c70f846762e\DEM.OS.DLL
Hidden in memory Handle opened
0x0505000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2764.39438__90ba9c70f846762e\ATIDEMOS.DLL
Hidden in memory Handle opened
0x050A000032.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0703.dll
Hidden in memory Handle opened
0x050D000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2764.39466__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x051E000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2729.30216__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL
Hidden in memory Handle opened
0x051F000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2764.39668__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0521000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2729.30243__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.DLL
Hidden in memory Handle opened
0x0522000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2729.30230__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0523000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2729.30212__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0524000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2764.39601__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0545000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2729.30213__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.DLL
Hidden in memory Handle opened
0x056C000088.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2764.39709__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0580000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2729.30231__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0592000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2764.39502__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0593000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2729.30219__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0594000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2729.30224__90ba9c70f846762e\AEM.Plugin.GD.Shared.DLL
Hidden in memory Handle opened
0x0595000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2764.39521__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0597000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2729.30219__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0598000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2764.39633__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0599000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2729.30228__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL
Hidden in memory Handle opened
0x059C000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2764.39609__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x059E000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2729.30226__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.DLL
Hidden in memory Handle opened
0x059F000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2764.39654__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x05A0000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2729.30259__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.DLL
Hidden in memory Handle opened
0x05B2000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2764.39601__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x05B4000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2729.30225__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.DLL
Hidden in memory Handle opened
0x05B5000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2729.30231__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0617000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2764.39675__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x061C000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2764.39609__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x061E000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2729.30227__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0631000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2764.39738__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL
Hidden in memory Handle opened
0x0632000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2729.30262__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL
Hidden in memory Handle opened
0x0644000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.2764.39437__90ba9c70f846762e\APM.Server.DLL
Hidden in memory Handle opened
0x0645000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2729.30208__90ba9c70f846762e\APM.Foundation.DLL
Hidden in memory Handle opened
0x06570000334.33 KbData
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorrc.dll
Signed
0x065D000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2729.30205__90ba9c70f846762e\CLI.Component.Client.Shared.Private.DLL
Hidden in memory Handle opened
0x066E0000448.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2764.39723__90ba9c70f846762e\CLI.Component.Systemtray.DLL
Hidden in memory Handle opened
0x0675000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2729.30185__90ba9c70f846762e\CLI.Component.Client.Shared.DLL
Hidden in memory Handle opened
0x0678000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2729.30211__90ba9c70f846762e\CLI.Component.Wizard.Shared.DLL
Hidden in memory Handle opened
0x0689000032.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
Hidden in memory Handle opened
0x068A000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2729.30258__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.DLL
Hidden in memory Handle opened
0x068B000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2729.30216__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.DLL
Hidden in memory Handle opened
0x06AC000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2764.39480__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x06AD0000104.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2764.39682__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x06B1000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2729.30264__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.DLL
Hidden in memory Handle opened
0x06C20000472.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2764.39475__90ba9c70f846762e\CLI.Component.Wizard.DLL
Hidden in memory Handle opened
0x06CA0000488.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2764.39745__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x06D20000312.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2764.39522__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x06D8000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.DLL
Hidden in memory Handle opened
0x06D90000408.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2764.39695__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x06F0000011.26 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\27b0a88bfa56a9390f516b0fa55f3dcb\System.Web.ni.dll
0x07A50000192.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2764.39503__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x07A9000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2729.30199__90ba9c70f846762e\CLI.Component.Dashboard.Shared.DLL
Hidden in memory Handle opened
0x07BB0000368.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.2764.39718__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x07C100001.45 MbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2764.39454__90ba9c70f846762e\CLI.Component.Dashboard.DLL
Hidden in memory Handle opened
0x07D9000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2729.30214__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.DLL
Hidden in memory Handle opened
0x07DA000088.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2764.39459__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x07DC000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2729.30241__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.DLL
Hidden in memory Handle opened
0x07DD0000144.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2764.39752__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x07E00000440.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2764.39467__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x07E80000216.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2764.39509__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x07EC0000128.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2764.39634__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x080200001.61 MbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2764.39489__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL
Hidden in memory Handle opened
0x081C0000480.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2764.39603__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x08240000408.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2764.39655__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x084E0000888.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2764.39711__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x088E0000336.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2764.39676__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x08940000592.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2764.39516__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x089E0000784.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2764.39611__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.DLL
Hidden in memory Handle opened
0x10000000260.00 KbImage
C:\Windows\System32\atipdlxx.dll
Signed
0x67DB0000784.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.2764.39611__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.DLL
Handle opened
0x67E80000592.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.2764.39516__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.DLL
Handle opened
0x67F20000336.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.2764.39676__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.DLL
Handle opened
0x67F80000888.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Dashboard\2.0.2764.39711__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Dashboard.DLL
Handle opened
0x68060000408.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.2764.39655__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.DLL
Handle opened
0x680D0000480.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.2764.39603__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.DLL
Handle opened
0x68150000128.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.2764.39634__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.DLL
Handle opened
0x68170000216.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.2764.39509__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.DLL
Handle opened
0x681B0000440.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Dashboard\2.0.2764.39467__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Dashboard.DLL
Handle opened
0x68220000144.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.2764.39752__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.DLL
Handle opened
0x6825000088.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.2764.39459__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.DLL
Handle opened
0x6828000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.2729.30241__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.DLL
Handle opened
0x682900001.45 MbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.2764.39454__90ba9c70f846762e\CLI.Component.Dashboard.DLL
Handle opened
0x68410000368.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Wizard\2.0.2764.39718__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Wizard.DLL
Handle opened
0x68470000192.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.2764.39503__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.DLL
Handle opened
0x684A0000312.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.2764.39522__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.DLL
Handle opened
0x684F000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.2729.30214__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.DLL
Handle opened
0x6850000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.2729.30199__90ba9c70f846762e\CLI.Component.Dashboard.Shared.DLL
Handle opened
0x68510000408.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.2764.39695__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.DLL
Handle opened
0x685800001.61 MbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.2764.39489__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.DLL
Handle opened
0x68720000104.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.2764.39682__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.DLL
Handle opened
0x68740000488.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.2764.39745__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.DLL
Handle opened
0x687C0000472.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.2764.39475__90ba9c70f846762e\CLI.Component.Wizard.DLL
Handle opened
0x68840000964.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\207b1e1e2254c7a308efe4f903e52ce2\System.Configuration.ni.dll
0x6894000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.DLL
Handle opened
0x6895000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.2729.30216__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.DLL
Handle opened
0x6896000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.2729.30264__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.DLL
Handle opened
0x6897000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.2764.39480__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.DLL
Handle opened
0x6898000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.2729.30258__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.DLL
Handle opened
0x6899000032.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
Handle opened
0x689A000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.2729.30211__90ba9c70f846762e\CLI.Component.Wizard.Shared.DLL
Handle opened
0x689B0000448.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Systemtray\2.0.2764.39723__90ba9c70f846762e\CLI.Component.Systemtray.DLL
Handle opened
0x68A3000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.2729.30205__90ba9c70f846762e\CLI.Component.Client.Shared.Private.DLL
Handle opened
0x68A4000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\APM.Foundation\2.0.2729.30208__90ba9c70f846762e\APM.Foundation.DLL
Handle opened
0x68A5000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\APM.Server\2.0.2764.39437__90ba9c70f846762e\APM.Server.DLL
Handle opened
0x68A6000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.2729.30262__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.DLL
Handle opened
0x68A7000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.2764.39738__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.DLL
Handle opened
0x68A8000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.2729.30185__90ba9c70f846762e\CLI.Component.Client.Shared.DLL
Handle opened
0x68A9000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.2729.30227__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.DLL
Handle opened
0x68AA000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.2764.39609__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.DLL
Handle opened
0x68AC000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.2729.30231__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.DLL
Handle opened
0x68AD000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.2764.39675__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.DLL
Handle opened
0x68AF000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.2729.30225__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.DLL
Handle opened
0x68B0000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.2764.39601__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.DLL
Handle opened
0x68B2000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.2764.39654__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.DLL
Handle opened
0x68B3000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.2729.30226__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.DLL
Handle opened
0x68B4000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.2764.39609__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.DLL
Handle opened
0x68B5000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.2729.30259__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.DLL
Handle opened
0x68B6000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.2729.30228__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.DLL
Handle opened
0x68B7000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.2729.30219__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.DLL
Handle opened
0x68B8000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.2764.39633__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.DLL
Handle opened
0x68B9000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.2764.39521__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.DLL
Handle opened
0x68BA000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Shared\2.0.2729.30219__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Shared.DLL
Handle opened
0x68BB000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.2729.30231__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.DLL
Handle opened
0x68F8000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Runtime\2.0.2764.39502__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Runtime.DLL
Handle opened
0x68F9000088.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.2764.39709__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.DLL
Handle opened
0x68FB000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.2729.30213__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.DLL
Handle opened
0x68FC000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.2729.30224__90ba9c70f846762e\AEM.Plugin.GD.Shared.DLL
Handle opened
0x68FD000032.00 KbImage
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\DEM.Graphics.I0703.dll
Handle opened
0x68FE000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.2729.30212__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.DLL
Handle opened
0x68FF000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.2729.30230__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.DLL
Handle opened
0x6900000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.2729.30243__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.DLL
Handle opened
0x6909000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.2764.39668__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.DLL
Handle opened
0x690B000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\ATIDEMOS\2.0.2764.39438__90ba9c70f846762e\ATIDEMOS.DLL
Handle opened
0x690D0000248.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.2764.39446__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.DLL
Handle opened
0x6914000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.OS\2.0.2729.30242__90ba9c70f846762e\DEM.OS.DLL
Handle opened
0x6915000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.2729.30197__90ba9c70f846762e\AEM.Actions.CCAA.Shared.DLL
Handle opened
0x6916000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.OS.I0602\2.0.2729.30259__90ba9c70f846762e\DEM.OS.I0602.DLL
Handle opened
0x691E000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.2729.30216__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.DLL
Handle opened
0x691F000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\ACE.Graphics.DisplaysManager.Shared\2.0.2573.17685__90ba9c70f846762e\ACE.Graphics.DisplaysManager.Shared.DLL
Handle opened
0x6930000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.2729.30199__90ba9c70f846762e\CLI.Caste.Graphics.Shared.DLL
Handle opened
0x697D0000988.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\a3a76226460de2153a62bdbfed9228b9\System.Management.ni.dll
0x6A31000040.00 KbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\WMINet_Utils.dll
Signed
0x6A670000612.00 KbImage
C:\Windows\System32\wbem\fastprox.dll
Signed
0x6A7100005.21 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\49431ce6d568de0bafdb1b25d3942723\System.Xml.ni.dll
0x6B19000011.87 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\b0be4ac8da47fbf783dabd1505e6c55e\System.Windows.Forms.ni.dll
0x6BEB000092.00 KbImage
C:\Windows\System32\wbem\wmiutils.dll
Signed
0x6BF00000352.00 KbImage
C:\Windows\System32\ATIDEMGX.dll
Signed Handle opened
0x6BF9000064.00 KbImage
C:\Windows\System32\wbem\wbemsvc.dll
Signed
0x6BFA000044.00 KbImage
C:\Windows\System32\wbem\wbemprox.dll
Signed
0x6C51000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Graphics\2.0.2729.30256__90ba9c70f846762e\DEM.Graphics.DLL
Handle opened
0x6C53000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.DLL
Handle opened
0x6C54000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.2729.30202__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.DLL
Handle opened
0x6C55000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.2729.30222__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.DLL
Handle opened
0x6C58000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.2764.39776__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.DLL
Handle opened
0x6C7E000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.2729.30201__90ba9c70f846762e\AEM.Server.Shared.DLL
Handle opened
0x6C7F000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.DLL
Handle opened
0x6C80000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.2729.30212__90ba9c70f846762e\AEM.Plugin.EEU.Shared.DLL
Handle opened
0x6C81000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Foundation\2.0.2729.30176__90ba9c70f846762e\AEM.Foundation.DLL
Handle opened
0x6C82000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.2764.39436__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.DLL
Handle opened
0x6C83000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\AEM.Server\2.0.2764.39436__90ba9c70f846762e\AEM.Server.DLL
Handle opened
0x6C84000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.DLL
Handle opened
0x6C880000772.00 KbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\e515919524c6be56f55ad12fbdd23c19\System.Runtime.Remoting.ni.dll
0x6C9500001.53 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\07e39e61fd6133a92333a2c98f2ffeb7\System.Drawing.ni.dll
0x6CAE000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2729.30203__90ba9c70f846762e\CLI.Component.Runtime.Shared.DLL
Handle opened
0x6CAF000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.2729.30193__90ba9c70f846762e\CLI.Foundation.Private.DLL
Handle opened
0x6CB3000056.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.2729.30209__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.DLL
Handle opened
0x6CB4000080.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.2764.39438__90ba9c70f846762e\CLI.Component.Runtime.DLL
Handle opened
0x6CBF000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.2729.30313__90ba9c70f846762e\CLI.Foundation.XManifest.DLL
Handle opened
0x6CC0000040.00 KbImage
C:\Windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.2729.30184__90ba9c70f846762e\NEWAEM.Foundation.DLL
Handle opened
0x6CFD000064.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Foundation\2.0.2729.30178__90ba9c70f846762e\CLI.Foundation.DLL
Handle opened
0x6CFE0000364.00 KbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorjit.dll
Signed
0x6D39000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.2729.30211__90ba9c70f846762e\LOG.Foundation.Implementation.Private.DLL
Handle opened
0x6E8A000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.2764.39601__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.DLL
Handle opened
0x6E8B000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.2764.39466__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.DLL
Handle opened
0x701E00007.52 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\System\34942db56010e4225825bfae8a27559f\System.ni.dll
0x7097000010.97 MbImage
C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\3aac7b97549d4ccf0c7dca3d1777f9b4\mscorlib.ni.dll
0x71650000364.00 KbImage
C:\Windows\System32\wbemcomn.dll
Signed
0x71F700005.56 MbImage
C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
Signed
0x729F0000620.00 KbImage
C:\Windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4053_none_d08d7da0442a985d\msvcr80.dll
Signed
0x72B50000280.00 KbImage
C:\Windows\System32\mscoree.dll
Signed
0x72FB000020.00 KbImage
C:\Windows\System32\shfolder.dll
Signed
0x7445000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\CCC.Implementation\2.0.2764.39730__90ba9c70f846762e\CCC.Implementation.DLL
Handle opened
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x7492000032.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Foundation\2.0.2729.30207__90ba9c70f846762e\MOM.Foundation.DLL
Handle opened
0x7493000072.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.2764.39729__90ba9c70f846762e\LOG.Foundation.Implementation.DLL
Handle opened
0x7495000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.2729.30188__90ba9c70f846762e\LOG.Foundation.Private.DLL
Handle opened
0x749B000048.00 KbImage
C:\Windows\assembly\GAC_MSIL\LOG.Foundation\2.0.2729.30174__90ba9c70f846762e\LOG.Foundation.DLL
Handle opened
0x749C0000112.00 KbImage
C:\Windows\assembly\GAC_MSIL\MOM.Implementation\2.0.2764.39730__90ba9c70f846762e\MOM.Implementation.DLL
Handle opened
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7503000032.00 KbImage
C:\Windows\System32\cfgmgr32.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
SynToshiba.exe ( PID : 3316 ) - 23 Modules
0x00400000204.00 KbImage
C:\Program Files\Synaptics\SynTP\SynToshiba.exe
Signed
0x004400003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x10000000160.00 KbImage
C:\Windows\System32\SynCOM.dll
Signed
0x63010000152.00 KbImage
C:\Windows\System32\SynTPAPI.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
Vba32arkit.exe ( PID : 4552 ) - 75 Modules
0x000D000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x0037000012.00 KbDataC:\Windows\System32\en-US\imageres.dll.muiHandle opened
0x004D00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x00DA000048.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.datHandle opened
0x00DB000032.00 KbDataC:\Users\Punymicro\AppData\Roaming\Microsoft\Windows\Cookies\index.datHandle opened
0x00DC000032.00 KbDataC:\Users\Punymicro\AppData\Local\Microsoft\Windows\History\History.IE5\index.datHandle opened
0x00DE0000100.00 KbDataC:\Windows\System32\ieframe.dllHandle opened
0x00E0000016.00 KbDataC:\Windows\System32\stdole2.tlbHandle opened
0x00EA0000634.36 KbDataC:\Windows\Fonts\micross.ttfHandle opened
0x012A00001.40 MbImage
C:\Users\Punymicro\Desktop\backup\vba32arkit_beta\Vba32arkit.exe
ADS:Yes Signed
0x039E000015.09 MbData
C:\Windows\System32\imageres.dll
Signed
0x051800003.74 MbImage
C:\Windows\System32\atiumdva.dll
Signed
0x67CC000024.00 KbImage
C:\Windows\System32\dciman32.dll
Signed
0x68E30000348.00 KbImage
C:\Windows\System32\dxtmsft.dll
Signed
0x68E90000916.00 KbImage
C:\Windows\System32\ddraw.dll
Signed
0x69590000108.00 KbImage
C:\Windows\System32\cryptnet.dll
Signed
0x695D0000500.00 KbImage
C:\Windows\System32\jscript.dll
Signed
0x6975000040.00 KbImage
C:\Windows\System32\ddrawex.dll
Signed
0x6BFB000044.00 KbImage
C:\Windows\System32\msimtf.dll
Signed
0x6C1800003.45 MbImage
C:\Windows\System32\mshtml.dll
Signed
0x6CC10000192.00 KbImage
C:\Windows\System32\mlang.dll
Signed
0x6D260000164.00 KbImage
C:\Windows\System32\msls31.dll
Signed
0x6D4800005.81 MbImage
C:\Windows\System32\ieframe.dll
Signed Handle opened
0x6F63000024.00 KbImage
C:\Windows\System32\SensApi.dll
Signed
0x6FA000003.04 MbImage
C:\Windows\System32\atiumdag.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x726D0000228.00 KbImage
C:\Windows\System32\dxtrans.dll
Signed
0x736A0000112.00 KbImage
C:\Windows\System32\oledlg.dll
Signed
0x73DB000080.00 KbImage
C:\Windows\System32\atl.dll
Signed
0x743F000084.00 KbImage
C:\Windows\System32\cabinet.dll
Signed
0x746B00001.67 MbImage
C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6002.18005_none_9e50b396ca17ae07\GdiPlus.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x75070000264.00 KbImage
C:\Windows\System32\winspool.drv
Signed
0x751C000032.00 KbImage
C:\Windows\System32\version.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x752C000084.00 KbImage
C:\Windows\System32\gpapi.dll
Signed
0x75610000276.00 KbImage
C:\Windows\System32\bcrypt.dll
Signed
0x75660000212.00 KbImage
C:\Windows\System32\ncrypt.dll
Signed
0x757F0000232.00 KbImage
C:\Windows\System32\SLC.dll
Signed
0x75830000968.00 KbImage
C:\Windows\System32\crypt32.dll
Signed
0x759A000072.00 KbImage
C:\Windows\System32\msasn1.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75C70000380.00 KbImage
C:\Windows\System32\sxs.dll
Signed
0x75D30000176.00 KbImage
C:\Windows\System32\apphelp.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75DB0000120.00 KbImage
C:\Windows\System32\userenv.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x75FF0000832.00 KbImage
C:\Windows\System32\wininet.dll
Signed
0x760C0000276.00 KbImage
C:\Windows\System32\iertutil.dll
Signed
0x76110000460.00 KbImage
C:\Windows\System32\comdlg32.dll
Signed
0x7619000012.00 KbImage
C:\Windows\System32\normaliz.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x7630000011.06 MbImage
C:\Windows\System32\shell32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x76F600001.16 MbImage
C:\Windows\System32\urlmon.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x773C00001.54 MbImage
C:\Windows\System32\setupapi.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
ctfmon.exe ( PID : 4644 ) - 24 Modules
0x000500002.50 KbDataC:\Windows\System32\en-US\ctfmon.exe.muiHandle opened
0x002A00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x0078000020.00 KbImage
C:\Windows\System32\ctfmon.exe
Signed
0x015600003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x70170000172.00 KbImage
C:\Windows\System32\msutb.dll
Signed
0x701A000032.00 KbImage
C:\Windows\System32\MsCtfMonitor.dll
Signed
0x7147000048.00 KbImage
C:\Windows\System32\dwmapi.dll
Signed
0x74D300001.62 MbImage
C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
Signed
0x74ED0000252.00 KbImage
C:\Windows\System32\uxtheme.dll
Signed
0x7505000040.00 KbImage
C:\Windows\System32\wtsapi32.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x77550000356.00 KbImage
C:\Windows\System32\shlwapi.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
WmiPrvSE.exe ( PID : 4828 ) - 41 Modules
0x002700003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x005F000064.53 KbData
C:\Windows\System32\C_1256.NLS
Signed
0x0061000064.53 KbData
C:\Windows\System32\C_1251.NLS
Signed
0x0063000064.53 KbData
C:\Windows\System32\C_1250.NLS
Signed
0x007F0000192.03 KbData
C:\Windows\System32\C_950.NLS
Signed
0x0083000064.53 KbData
C:\Windows\System32\C_1253.NLS
Signed
0x0085000017.50 KbDataC:\Windows\System32\en-US\user32.dll.muiHandle opened
0x00C70000252.00 KbImage
C:\Windows\System32\wbem\WmiPrvSE.exe
Signed
0x00CB00003.49 MbData
C:\Windows\System32\locale.nls
Signed
0x69660000160.00 KbImage
C:\Windows\System32\wbem\wmiprov.dll
Signed
0x6A670000612.00 KbImage
C:\Windows\System32\wbem\fastprox.dll
Signed
0x6AD9000012.00 KbImage
C:\Windows\System32\wmi.dll
Signed
0x6BEB000092.00 KbImage
C:\Windows\System32\wbem\wmiutils.dll
Signed
0x6BF9000064.00 KbImage
C:\Windows\System32\wbem\wbemsvc.dll
Signed
0x71650000364.00 KbImage
C:\Windows\System32\wbemcomn.dll
Signed
0x751D0000132.00 KbImage
C:\Windows\System32\ntmarta.dll
Signed
0x75200000236.00 KbImage
C:\Windows\System32\rsaenh.dll
Signed
0x7598000096.00 KbImage
C:\Windows\System32\ntdsapi.dll
Signed
0x759C000068.00 KbImage
C:\Windows\System32\samlib.dll
Signed
0x759E0000176.00 KbImage
C:\Windows\System32\dnsapi.dll
Signed
0x75BF0000472.00 KbImage
C:\Windows\System32\netapi32.dll
Signed
0x75D6000060.00 KbImage
C:\Windows\System32\ncobjapi.dll
Signed
0x75D9000080.00 KbImage
C:\Windows\System32\secur32.dll
Signed
0x75EF000028.00 KbImage
C:\Windows\System32\psapi.dll
Signed
0x75F00000300.00 KbImage
C:\Windows\System32\gdi32.dll
Signed
0x75F50000628.00 KbImage
C:\Windows\System32\user32.dll
Signed
0x761A0000528.00 KbImage
C:\Windows\System32\clbcatq.dll
Signed
0x76230000792.00 KbImage
C:\Windows\System32\advapi32.dll
Signed
0x76E100001.27 MbImage
C:\Windows\System32\ole32.dll
Signed
0x7709000036.00 KbImage
C:\Windows\System32\lpk.dll
Signed
0x770A0000800.00 KbImage
C:\Windows\System32\msctf.dll
Signed
0x77170000564.00 KbImage
C:\Windows\System32\oleaut32.dll
Signed
0x77230000680.00 KbImage
C:\Windows\System32\msvcrt.dll
Signed
0x772E0000880.00 KbImage
C:\Windows\System32\kernel32.dll
Signed
0x775B0000120.00 KbImage
C:\Windows\System32\imm32.dll
Signed
0x775D0000500.00 KbImage
C:\Windows\System32\usp10.dll
Signed
0x77650000180.00 KbImage
C:\Windows\System32\ws2_32.dll
Signed
0x776800001.15 MbImage
C:\Windows\System32\ntdll.dll
Signed
0x777B000024.00 KbImage
C:\Windows\System32\nsi.dll
Signed
0x777C0000292.00 KbImage
C:\Windows\System32\Wldap32.dll
Signed
0x77810000780.00 KbImage
C:\Windows\System32\rpcrt4.dll
Signed
Up

Autorun objects

Don't display trusted items

NameImage PathState
Quick Launch (6 objects)
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnkC:\PROGRA~1\INTERN~1\iexplore.exe, C:\Program Files\Internet Explorer\iexplore.exeSigned
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnkC:\PROGRA~1\MOZILL~1\firefox.exe, C:\Program Files\Mozilla Firefox\firefox.exe, C:\Program Files\Mozilla Firefox\firefox.exeSigned
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Sandboxed Web Browser.lnkC:\PROGRA~1\SANDBO~1\Start.exe, C:\Program Files\Sandboxie\Start.exe, default_browserSigned
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk%SystemRoot%\system32\imageres.dllSigned
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk%SystemRoot%\explorer.exeSigned
C:\Users\Punymicro\Application Data\Microsoft\Internet Explorer\Quick Launch\Windows Media Player.lnkC:\PROGRA~1\WI4EB4~1\wmplayer.exe, C:\Program Files\Windows Media Player\wmplayer.exe, /prefetch:1Signed
Registry\Autostart Keys (11 objects)
SandboxieControl
"C:\Program Files\Sandboxie\SbieCtrl.exe"Signed
TOSCDSPD
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
AntiLogger
"C:\Program Files\AntiLogger\AntiLogger.exe" /minimizedSigned
Malwarebytes' Anti-Malware (reboot)
"C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscriptSigned
Privatefirewall
C:\Program Files\Privacyware\Privatefirewall 7.0\PFGUI.exeSigned
RtHDVCpl
RtHDVCpl.exeSigned
StartCCC
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
SunJavaUpdateSched
"C:\Program Files\Common Files\Java\Java Update\jusched.exe"Signed
SynTPStart
C:\Program Files\Synaptics\SynTP\SynTPStart.exeSigned
SandboxieControl
"C:\Program Files\Sandboxie\SbieCtrl.exe"Signed
TOSCDSPD
C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe
Registry\Windows WinLogon (3 objects)
Shell
Explorer.exeSigned
Userinit
C:\Windows\system32\userinit.exe,Signed
VmApplet
rundll32 shell32,Control_RunDLL "sysdm.cpl"Signed
Registry\ActiveX (9 objects)
>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}C:\Windows\system32\unregmp2.exe /ShowWMPSigned
>{26923b43-4d38-484f-9b9e-de460746276c}C:\Windows\system32\ie4uinit.exe -UserIconConfigSigned
>{60B49E34-C7CC-11D0-8953-00A0C90347FF}RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUPSigned
{2C7339CF-2B09-4501-B3F3-F3508C9228ED}%SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dllSigned
{44BBA840-CC51-11CF-AAFA-00AA00B6015C}"%ProgramFiles%\Windows Mail\WinMail.exe" OCInstallUserConfigOESigned
{6BF52A52-394A-11d3-B153-00C04F79FAA6}%SystemRoot%\system32\unregmp2.exe /FirstLogon /Shortcuts /RegBrowsers /ResetMUISigned
{89820200-ECBD-11cf-8B85-00AA005B4340}regsvr32.exe /s /n /i:U shell32.dllSigned
{89820200-ECBD-11cf-8B85-00AA005B4383}C:\Windows\system32\ie4uinit.exe -BaseSettingsSigned
{89B4C1CD-B018-4511-B0A1-5476DBF70820}C:\Windows\system32\Rundll32.exe C:\Windows\system32\mscories.dll,InstallSigned
Registry\WinLogon Notify (12 objects)
{0ACDD40C-75AC-47ab-BAA0-BF6DE7E7FE63}
wlgpclnt.dllSigned
{25537BA6-77A8-11D2-9B6C-0000F8080861}
fdeploy.dllSigned
{3610eda5-77ef-11d2-8dc5-00c04fa31a66}
%SystemRoot%\System32\dskquota.dllSigned
{426031c0-0b47-4852-b0ca-ac3d37bfcb39}
gptext.dllSigned
{4CFB60C1-FAA6-47f1-89AA-0B18730C9FD3}
iedkcs32.dllSigned
{7933F41E-56F8-41d6-A31C-4148A711EE93}
%SystemRoot%\System32\srchadmin.dllSigned
{827D319E-6EAC-11D2-A4EA-00C04F79F83A}
scecli.dllSigned
{A2E30F80-D7DE-11d2-BBDE-00C04F86AE3B}
iedkcs32.dllSigned
{B1BE8D72-6EAC-11D2-A4EA-00C04F79F83A}
scecli.dllSigned
{B587E2B1-4D59-4e7e-AED9-22B9DF11D053}
dot3gpclnt.dllSigned
{FB2CA36D-0B40-4307-821B-A13B252DE56C}
gptext.dllSigned
{e437bc1c-aa7d-11d2-a382-00c04f991e27}
%SystemRoot%\System32\polstore.dllSigned
Registry\Security Providers (1 object)
SecurityProviderscredssp.dllSigned
Registry\Print (8 objects)
Driver
localspl.dllSigned
Driver
tcpmon.dllSigned
Driver
tbtmon.dll
Driver
usbmon.dllSigned
Driver
WSDMon.dllSigned
Driver
hpf3l083.dll
Name
inetpp.dllSigned
Name
win32spl.dllSigned
Registry\Value Run Keys (8 objects)
ProviderPath
%SystemRoot%\system32\ntmarta.dllSigned
AlternateShell
cmd.exeSigned
BootExecute
autocheck autochk *Signed
StartupPrograms
rdpclip
SCRNSAVE.EXE
C:\Windows\system32\logon.scrSigned
SCRNSAVE.EXE
C:\Windows\system32\logon.scrSigned
SCRNSAVE.EXE
C:\Windows\system32\logon.scrSigned
SCRNSAVE.EXE
C:\Windows\system32\logon.scrSigned
Explorer\Shared Task Scheduler (1 object)
{8C7461EF-2B13-11d2-BE35-3078302C2030}%SystemRoot%\system32\browseui.dllSigned
Registry\Shell Service Object Delay Load (1 object)
WebCheckC:\Windows\system32\webcheck.dllSigned
Registry\My Computer (Backup, Cleanup, Defrag utilities) (3 objects)
BackupPath
%SystemRoot%\system32\sdclt.exeSigned
CleanupPath
%SystemRoot%\System32\cleanmgr.exe /D %cSigned
DefragPath
%systemroot%\system32\dfrgui.exeSigned
Internet Explorer\Browser Helper Objects (1 object)
{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dllSigned
Internet Explorer\URLSearchHooks (1 object)
{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
C:\Windows\system32\ieframe.dllSigned
Parameters\ServiceDll (101 objects)
AeLookupSvc%SystemRoot%\System32\aelupsvc.dllSigned
Appinfo%SystemRoot%\System32\appinfo.dllSigned
AppMgmt%SystemRoot%\System32\appmgmts.dll
AudioEndpointBuilder%SystemRoot%\System32\Audiosrv.dllSigned
Audiosrv%SystemRoot%\System32\Audiosrv.dllSigned
BFE%SystemRoot%\System32\bfe.dllSigned
BITS%systemroot%\system32\qmgr.dllSigned
Browser%SystemRoot%\System32\browser.dllSigned
CertPropSvc%SystemRoot%\System32\certprop.dllSigned
CryptSvc%SystemRoot%\system32\cryptsvc.dllSigned
DcomLaunch%SystemRoot%\system32\rpcss.dllSigned
Dhcp%SystemRoot%\System32\dhcpcsvc.dllSigned
Dnscache%SystemRoot%\System32\dnsrslvr.dllSigned
dot3svc%SystemRoot%\System32\dot3svc.dllSigned
DPS%SystemRoot%\system32\dps.dllSigned
EapHost%SystemRoot%\System32\eapsvc.dllSigned
ehstart%SystemRoot%\ehome\ehstart.dllSigned
EMDMgmt%systemroot%\system32\emdmgmt.dllSigned
EventSystem%systemroot%\system32\es.dllSigned
fdPHost%SystemRoot%\system32\fdPHost.dllSigned
FDResPub%SystemRoot%\system32\fdrespub.dllSigned
gpsvc%SystemRoot%\System32\gpsvc.dllSigned
hidserv%SystemRoot%\System32\hidserv.dllSigned
hkmsvc%SystemRoot%\system32\kmsvc.dllSigned
IKEEXT%SystemRoot%\System32\ikeext.dllSigned
IPBusEnum%SystemRoot%\system32\ipbusenum.dllSigned
iphlpsvc%SystemRoot%\System32\iphlpsvc.dllSigned
KtmRm%systemroot%\system32\msdtckrm.dllSigned
LanmanServer%SystemRoot%\System32\srvsvc.dllSigned
LanmanWorkstation%SystemRoot%\System32\wkssvc.dllSigned
lltdsvc%SystemRoot%\System32\lltdsvc.dllSigned
lmhosts%SystemRoot%\System32\lmhsvc.dllSigned
Mcx2Svc%SystemRoot%\system32\Mcx2Svc.dllSigned
MMCSS%SystemRoot%\system32\mmcss.dllSigned
MpsSvc%SystemRoot%\system32\mpssvc.dllSigned
MSiSCSI%systemroot%\system32\iscsiexe.dllSigned
napagent%SystemRoot%\system32\qagentRT.dllSigned
Net Driver HPZ12C:\Windows\system32\HPZinw12.dll
Netman%SystemRoot%\System32\netman.dllSigned
netprofm%SystemRoot%\System32\netprofm.dllSigned
NlaSvc%SystemRoot%\System32\nlasvc.dllSigned
nsi%systemroot%\system32\nsisvc.dllSigned
p2pimsvc%SystemRoot%\system32\p2psvc.dllSigned
p2psvc%SystemRoot%\system32\p2psvc.dllSigned
PcaSvc%SystemRoot%\System32\pcasvc.dllSigned
pla%systemroot%\system32\pla.dllSigned
PlugPlay%SystemRoot%\system32\umpnpmgr.dllSigned
Pml Driver HPZ12C:\Windows\system32\HPZipm12.dll
PNRPAutoReg%SystemRoot%\system32\p2psvc.dllSigned
PNRPsvc%SystemRoot%\system32\p2psvc.dllSigned
PolicyAgent%SystemRoot%\System32\ipsecsvc.dllSigned
ProfSvc%systemroot%\system32\profsvc.dllSigned
QWAVE%windir%\system32\qwave.dllSigned
RasAuto%SystemRoot%\System32\rasauto.dllSigned
RasMan%SystemRoot%\System32\rasmans.dllSigned
RemoteAccess%SystemRoot%\System32\mprdim.dllSigned
RemoteRegistry%SystemRoot%\system32\regsvc.dllSigned
RpcSs%SystemRoot%\System32\rpcss.dllSigned
SCardSvr%SystemRoot%\System32\SCardSvr.dllSigned
Schedule%systemroot%\system32\schedsvc.dllSigned
SCPolicySvc%SystemRoot%\System32\certprop.dllSigned
SDRSVC%Systemroot%\System32\SDRSVC.dllSigned
seclogon%windir%\system32\seclogon.dllSigned
SENS%SystemRoot%\system32\sens.dllSigned
SessionEnv%SystemRoot%\system32\sessenv.dllSigned
SharedAccess%SystemRoot%\System32\ipnathlp.dllSigned
ShellHWDetection%SystemRoot%\System32\shsvcs.dllSigned
SLUINotify%SystemRoot%\system32\SLUINotify.dllSigned
SSDPSRV%SystemRoot%\System32\ssdpsrv.dllSigned
SstpSvc%SystemRoot%\system32\sstpsvc.dllSigned
stisvc%SystemRoot%\System32\wiaservc.dllSigned
swprv%Systemroot%\System32\swprv.dllSigned
SysMain%systemroot%\system32\sysmain.dllSigned
TabletInputService%SystemRoot%\System32\TabSvc.dllSigned
TapiSrv%SystemRoot%\System32\tapisrv.dllSigned
TBS%SystemRoot%\System32\tbssvc.dllSigned
TermService%SystemRoot%\System32\termsrv.dllSigned
Themes%SystemRoot%\system32\shsvcs.dllSigned
THREADORDER%SystemRoot%\system32\mmcss.dllSigned
TrkWks%SystemRoot%\System32\trkwks.dllSigned
upnphost%SystemRoot%\System32\upnphost.dllSigned
UxSms%SystemRoot%\System32\uxsms.dllSigned
W32Time%systemroot%\system32\w32time.dllSigned
wcncsvc%SystemRoot%\System32\wcncsvc.dllSigned
WcsPlugInService%SystemRoot%\System32\WcsPlugInService.dllSigned
WdiServiceHost%SystemRoot%\system32\wdi.dllSigned
WdiSystemHost%SystemRoot%\system32\wdi.dllSigned
WebClient%SystemRoot%\System32\webclnt.dllSigned
Wecsvc%SystemRoot%\system32\wecsvc.dllSigned
wercplsupport%SystemRoot%\System32\wercplsupport.dllSigned
WerSvc%SystemRoot%\System32\WerSvc.dllSigned
WinDefend%ProgramFiles%\Windows Defender\mpsvc.dllSigned
WinHttpAutoProxySvcwinhttp.dllSigned
Winmgmt%SystemRoot%\system32\wbem\WMIsvc.dllSigned
WinRM%SystemRoot%\system32\WsmSvc.dllSigned
Wlansvc%SystemRoot%\System32\wlansvc.dllSigned
WPCSvc%SystemRoot%\System32\wpcsvc.dllSigned
WPDBusEnum%SystemRoot%\system32\wpdbusenum.dllSigned
wscsvc%SYSTEMROOT%\system32\wscsvc.dllSigned
wuauserv%systemroot%\system32\wuaueng.dllSigned
wudfsvc%SystemRoot%\System32\WUDFSvc.dllSigned
Performance\Library (34 objects)
.NET CLR Datanetfxperf.dllSigned
.NET CLR Networkingnetfxperf.dllSigned
.NET Data Provider for Oraclenetfxperf.dllSigned
.NET Data Provider for SqlServernetfxperf.dllSigned
.NETFrameworkmscoree.dllSigned
BITSbitsperf.dllSigned
EmdCache%systemroot%\system32\emdmgmt.dllSigned
ESENT%systemroot%\system32\esentprf.dllSigned
LsaSecur32.dllSigned
MSDTCmsdtcuiu.DLLSigned
MSDTC Bridge 3.0.0.0NETFXPerf.dllSigned
MSSCNTRS%systemroot%\system32\msscntrs.dllSigned
PerfDiskperfdisk.dllSigned
PerfNetperfnet.dllSigned
PerfOSperfos.dllSigned
PerfProcperfproc.dllSigned
PNRPsvc%SystemRoot%\system32\pnrpperf.dllSigned
PolicyAgent%SystemRoot%\System32\ipsecsvc.dllSigned
PSchedpacerprf.dllSigned
RemoteAccessrasctrs.dllSigned
ServiceModelEndpoint 3.0.0.0NETFXPerf.dllSigned
ServiceModelOperation 3.0.0.0NETFXPerf.dllSigned
ServiceModelService 3.0.0.0NETFXPerf.dllSigned
SMSvcHost 3.0.0.0NETFXPerf.dllSigned
Spoolerwinspool.drvSigned
TapiSrvtapiperf.dllSigned
TcpipPerfctrs.dllSigned
TermServiceperfts.dllSigned
UGatherer%systemroot%\system32\msscntrs.dllSigned
UGTHRSVC%systemroot%\system32\msscntrs.dllSigned
usbhub%SystemRoot%\system32\usbperf.dllSigned
Windows Workflow Foundation 3.0.0.0netfxperf.dllSigned
WmiApRpl%systemroot%\system32\wbem\wmiaprpl.dllSigned
WSearchIdxPi%systemroot%\system32\tquery.dllSigned
Explorer\Context Menu (12 objects)
7-Zip
C:\Program Files\7-Zip\7-zip.dll
BriefcaseMenu
syncui.dllSigned
Notepad++
C:\Program Files\Notepad++\NppShell_04.dll
Open With
%SystemRoot%\system32\shell32.dllSigned
Open With EncryptionMenu
%SystemRoot%\system32\shell32.dllSigned
Sharing
ntshrui.dllSigned
{a2a9545d-a0c2-42b4-9708-a0b2badd77c8}
%SystemRoot%\system32\shell32.dllSigned
BriefcasePage
syncui.dllSigned
CryptoSignMenu
%SystemRoot%\system32\cryptext.dllSigned
{1f2e5c40-9550-11ce-99d2-00aa006e086c}
rshx32.dllSigned
{3EA48300-8CF6-101B-84FB-666CCB9BCD32}
docprop.dllSigned
{883373C3-BF89-11D1-BE35-080036B11A03}
%SystemRoot%\system32\shell32.dllSigned
Explorer\Shell Extensions (286 objects)
{00020d75-0000-0000-c000-000000000046}
lnkfile
{00021401-0000-0000-C000-000000000046}
shell32.dllSigned
{00BB2763-6A77-11D0-A535-00C04FD7D062}
%SystemRoot%\system32\browseui.dllSigned
{00BB2764-6A77-11D0-A535-00C04FD7D062}
%SystemRoot%\system32\browseui.dllSigned
{00BB2765-6A77-11D0-A535-00C04FD7D062}
%SystemRoot%\system32\browseui.dllSigned
{00f20eb5-8fd6-4d9d-b75e-36801766c8f1}
%ProgramFiles%\Windows Photo Gallery\PhotoAcq.dllSigned
{00f2886f-cd64-4fc9-8ec5-30ef6cdbe8c3}
Microsoft.ScannersAndCameras
{01E04581-4EEE-11d0-BFE9-00AA005B4383}
%SystemRoot%\system32\browseui.dllSigned
{025A5937-A6BE-4686-A844-36FE4BEC8B6D}
%SystemRoot%\System32\shdocvw.dllSigned
{031EE060-67BC-460d-8847-E4A7C5E45A27}
"%ProgramFiles%\Windows Media Player\wmprph.exe"Signed
{03C036F1-A186-11D0-824A-00AA005B4383}
%SystemRoot%\system32\browseui.dllSigned
{056440FD-8568-48e7-A632-72157243B55B}
%SystemRoot%\system32\browseui.dllSigned
{07C45BB1-4A8C-4642-A1F5-237E7215FF66}
C:\Windows\system32\ieframe.dllSigned
{08165EA0-E946-11CF-9C87-00AA005127ED}
C:\Windows\system32\webcheck.dllSigned
{0AFCCBA6-BF90-4A4E-8482-0AC960981F5B}
%SystemRoot%\system32\shell32.dllSigned
{0BFCF7B7-E7B6-433a-B205-2904FCF040DD}
%SystemRoot%\System32\appwiz.cplSigned
{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}
cabview.dllSigned
{0D45D530-764B-11d0-A1CA-00AA00C16E65}
%systemroot%\system32\dsuiext.dllSigned
{0DF44EAA-FF21-4412-828E-260A8728E7F1}
Taskbar and Start Menu
{0F8604A5-4ECE-4DE1-BA7D-CF10F8AA4F48}
Contacts folder
{0a4286ea-e355-44fb-8086-af3df7645bd9}
C:\PROGRA~1\WI4EB4~1\wmpband.dllSigned
{11dbb47c-a525-400b-9e80-a54615a090c0}
ExplorerFrame.dllSigned
{13D3C4B8-B179-4ebb-BF62-F704173E7448}
%CommonProgramFiles%\System\wab32.dllSigned
{143A62C8-C33B-11D1-84FE-00C04FA34A14}
%SystemRoot%\MSAgent\agentpsh.dllSigned
{1531d583-8375-4d3f-b5fb-d23bbd169f22}
%SystemRoot%\system32\shell32.dllSigned
{15D633E2-AD00-465b-9EC7-F56B7CDF8E27}
%CommonProgramFiles%\microsoft shared\ink\TipBand.dllSigned
{15eae92e-f17a-4431-9f28-805e482dafd4}
%SystemRoot%\System32\appwiz.cplSigned
{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}
%SystemRoot%\system32\dsquery.dllSigned
{169A0691-8DF9-11d1-A1C4-00C04FD75D13}
%SystemRoot%\system32\browseui.dllSigned
{16C2C29D-0E5F-45f3-A445-03E03F587B7D}
%CommonProgramFiles%\System\wab32.dllSigned
{176d6597-26d3-11d1-b350-080036a75b03}
%SystemRoot%\System32\colorui.dllSigned
{17cd9488-1228-4b2f-88ce-4298e93e0966}
%SystemRoot%\System32\shdocvw.dllSigned
{1C1EDB47-CE22-4bbb-B608-77B48F83C823}
C:\Windows\system32\ieframe.dllSigned
{1F2E5C40-9550-11CE-99D2-00AA006E086C}
rshx32.dllSigned
{1FA9085F-25A2-489B-85D4-86326EEDCD87}
%SystemRoot%\system32\wlanpref.dllSigned
{1a184871-359e-4f67-aad9-5b9905d62232}
fontext.dllSigned
{1b24a030-9b20-49bc-97ac-1be4426f9e59}
ActiveDirectory Folder
{205D7A97-F16D-4691-86EF-F3075DCCA57D}
C:\Windows\system32\ieframe.dllSigned
{21569614-B795-46b1-85F4-E737A8DC09AD}
%SystemRoot%\system32\browseui.dllSigned
{21ec2020-3aea-1069-a2dd-08002b30309d}
shell32.dllSigned
{2206CDB2-19C1-11D1-89E0-00C04FD7A829}
%CommonProgramFiles%\System\Ole DB\oledb32.dllSigned
{23170F69-40C1-278A-1000-000100020000}
C:\Program Files\7-Zip\7-zip.dll
{25336920-03f9-11cf-8fd0-00aa00686f13}
C:\Windows\system32\mshtml.dllSigned
{25585dc7-4da0-438d-ad04-e42c8d2d64b9}
%SystemRoot%\system32\shell32.dllSigned
{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f6-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}
%SystemRoot%\System32\shdocvw.dllSigned
{2781761E-28E0-4109-99FE-B9D127C57AFE}
%ProgramFiles%\Windows Defender\MpOav.dllSigned
{28803F59-3A75-4058-995F-4EE5503B023C}
%systemroot%\system32\FunctionDiscoveryFolder.dllSigned
{289978AC-A101-4341-A817-21EBA7FD046D}
%SystemRoot%\System32\SyncCenter.dllSigned
{2BC0DA0E-F1BC-43AB-B4B5-738EB6B51E7E}
fontext.dllSigned
{2C2577C2-63A7-40e3-9B7F-586602617ECB}
Explorer Query BandSigned
{2E9E59C0-B437-4981-A647-9C34B9B90891}
%SystemRoot%\System32\SyncCenter.dllSigned
{2F603045-309F-11CF-9774-0020AFD0CFF6}
C:\Program Files\Synaptics\SynTP\SynTPCpl.dllSigned
{3028902F-6374-48b2-8DC6-9725E775B926}
C:\Windows\system32\ieframe.dllSigned
{3050f3d9-98b5-11cf-bb82-00aa00bdce0b}
C:\Windows\system32\mshtml.dllSigned
{3080F90D-D7AD-11D9-BD98-0000947B0257}
%SystemRoot%\System32\shdocvw.dllSigned
{3080F90E-D7AD-11D9-BD98-0000947B0257}
%SystemRoot%\System32\shdocvw.dllSigned
{30D02401-6A81-11d0-8274-00C04FD5AE38}
C:\Windows\system32\ieframe.dllSigned
{32714800-2E5F-11d0-8B85-00AA0044F941}
%ProgramFiles%\Windows Mail\wabfind.dllSigned
{328B0346-7EAF-4BBE-A479-7CB88A095F5B}
%SystemRoot%\system32\shell32.dllSigned
{335a31dd-f04b-4d76-a925-d6b47cf360df}
%SystemRoot%\system32\shdocvw.dllSigned
{34449847-FD14-4fc8-A75A-7432F5181EFB}
ActiveDirectory Folder
{35786D3C-B075-49b9-88DD-029876E11C01}
%SystemRoot%\system32\wpdshext.dllSigned
{36eef7db-88ad-4e81-ad49-0e313f0c35f8}
%SystemRoot%\system32\shdocvw.dllSigned
{37efd44d-ef8d-41b1-940d-96973a50e9e0}
Windows Sidebar Properties
{38a98528-6cbf-4ca9-8dc0-b1e1d10f7b1b}
View Available Networks
{3C374A40-BAE4-11CF-BF7D-00AA006946EE}
C:\Windows\system32\ieframe.dllSigned
{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}
%SystemRoot%\system32\browseui.dllSigned
{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}
C:\Windows\system32\ieframe.dllSigned
{3EA48300-8CF6-101B-84FB-666CCB9BCD32}
docprop.dllSigned
{3F30C968-480A-4C6C-862D-EFC0897BB84B}
C:\Windows\system32\PhotoMetadataHandler.dllSigned
{3c2654c6-7372-4f6b-b310-55d6128f49d2}
%SystemRoot%\system32\shell32.dllSigned
{3e7efb4c-faf1-453d-89eb-56026875ef90}
Get Programs Online
{4026492f-2f69-46b8-b9bf-5654fc07e423}
Windows Firewall
{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}
%SystemRoot%\System32\mediametadatahandler.dllSigned
{40dd6e20-7c17-11ce-a804-00aa003ca9f6}
ntshrui.dllSigned
{41E300E0-78B6-11ce-849B-444553540000}
%SystemRoot%\system32\themeui.dllSigned
{42071712-76d4-11d1-8b24-00a0c9068ff3}
deskadp.dllSigned
{42071713-76d4-11d1-8b24-00a0c9068ff3}
deskmon.dllSigned
{4336a54d-038b-4685-ab02-99bb52d3fb8b}
%SystemRoot%\System32\shdocvw.dllSigned
{437ff9c0-a07f-4fa0-af80-84b6c6440a16}
%SystemRoot%\system32\shell32.dllSigned
{43886CD5-6529-41c4-A707-7B3C92C05E68}
C:\Windows\system32\ieframe.dllSigned
{44121072-A222-48f2-A58A-6D9AD51EBBE9}
%SystemRoot%\system32\XPSSHHDR.DLLSigned
{44C76ECD-F7FA-411c-9929-1B77BA77F524}
C:\Windows\system32\ieframe.dllSigned
{44f3dab6-4392-4186-bb7b-6282ccb7a9f6}
%SystemRoot%\system32\mydocs.dllSigned
{45670FA8-ED97-4F44-BC93-305082590BFB}
%SystemRoot%\system32\XPSSHHDR.DLLSigned
{4A1E5ACD-A108-4100-9E26-D2FAFA1BA486}
%SystemRoot%\System32\icsigd.dllSigned
{4B534112-3AF6-4697-A77C-D62CE9B9E7CF}
%SystemRoot%\System32\SyncCenter.dllSigned
{4B78D326-D922-44f9-AF2A-07805C2A3560}
C:\Windows\system32\ieframe.dllSigned
{4E40F770-369C-11d0-8922-00A024AB2DBB}
dssec.dllSigned
{4E5BFBF8-F59A-4e87-9805-1F9B42CC254A}
C:\Windows\System32\gameux.dllSigned
{4F58F63F-244B-4c07-B29F-210BE59BE9B4}
%CommonProgramFiles%\System\wab32.dllSigned
{4a7ded0a-ad25-11d0-98a8-0800361b1103}
%SystemRoot%\system32\mydocs.dllSigned
{4d5c8c2a-d075-11d0-b416-00c04fb90376}
%SystemRoot%\system32\browseui.dllSigned
{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}
%windir%\system32\acppage.dllSigned
{5399E694-6CE5-4D6C-8FCE-1D8870FDCBA0}
Control Panel command object for Start menuSigned
{53BEDF0B-4E5B-4183-8DC9-B844344FA104}
%SystemRoot%\system32\mssvp.dllSigned
{576C9E85-1300-4EF5-BF6B-D00509F4EDCD}
%SystemRoot%\System32\SyncCenter.dllSigned
{58E3C745-D971-4081-9034-86E34B30836A}
%SystemRoot%\System32\shdocvw.dllSigned
{59099400-57FF-11CE-BD94-0020AF85B590}
diskcopy.dllSigned
{596742A5-1393-4e13-8765-AE1DF71ACAFB}
%SystemRoot%\system32\browseui.dllSigned
{59be4990-f85c-11ce-aff7-00aa003ca9f6}
ntlanui2.dllSigned
{5DB2625A-54DF-11D0-B6C4-0800091AA605}
%SystemRoot%\System32\colorui.dllSigned
{5E2121EE-0300-11D4-8D3B-444553540000}
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll
{5E6AB780-7743-11CF-A12B-00AA004AE837}
%SystemRoot%\system32\browseui.dllSigned
{5FA29220-36A1-40f9-89C6-F4B384B7642E}
%SystemRoot%\system32\inetcomm.dllSigned
{5ea4f148-308c-46d7-98a9-49041b1dd468}
Mobility Center Control PanelSigned
{60254CA5-953B-11CF-8C96-00AA00B8708C}
C:\Windows\system32\wshext.dllSigned
{6038EF75-ABFC-4e59-AB6F-12D397F6568D}
C:\Windows\system32\ieframe.dllSigned
{60632754-c523-4b62-b45c-4172da012619}
%SystemRoot%\System32\shdocvw.dllSigned
{60fd46de-f830-4894-a628-6fa81bc0190d}
%SystemRoot%\system32\photowiz.dllSigned
{62AE1F9A-126A-11D0-A14B-0800361B1103}
%systemroot%\system32\dsuiext.dllSigned
{63da6ec0-2e98-11cf-8d82-444553540000}
%SystemRoot%\system32\msieftp.dllSigned
{640167b4-59b0-47a6-b335-a6b3c0695aea}
%SystemRoot%\system32\audiodev.dllSigned
{66742402-F9B9-11D1-A202-0000F81FEDEE}
%SystemRoot%\system32\shell32.dllSigned
{6756A641-DE71-11d0-831B-00AA005B4383}
%SystemRoot%\system32\browseui.dllSigned
{675F097E-4C4D-11D0-B6C1-0800091AA605}
%SystemRoot%\system32\colorui.dllSigned
{67718415-c450-4f3c-bf8a-b487642dc39b}
Windows Features
{692F0339-CBAA-47e6-B5B5-3B84DB604E87}
C:\Windows\system32\extmgr.dllSigned
{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}
%SystemRoot%\system32\browseui.dllSigned
{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE}
C:\Windows\system32\ieframe.dllSigned
{6CF48EF8-44CD-45d2-8832-A16EA016311B}
C:\Windows\system32\ieframe.dllSigned
{6D8BB3D3-9D87-4a91-AB56-4F30CFFEFE9F}
%SystemRoot%\system32\browseui.dllSigned
{6b33163c-76a5-4b6c-bf21-45de9cd503a1}
%SystemRoot%\System32\shwebsvc.dllSigned
{6b9228da-9c15-419e-856c-19e768a13bdc}
%ProgramFiles%\Windows Sidebar\sbdrop.dllSigned
{6dfd7c5c-2451-11d3-a299-00c04f8ef6af}
Folder Options
{7007ACC7-3202-11D1-AAD2-00805FC1270E}
%SystemRoot%\System32\netshell.dllSigned
{708e1662-b832-42a8-bbe1-0a77121e3908}
%SystemRoot%\system32\shell32.dllSigned
{71D99464-3B6B-475C-B241-E15883207529}
%SystemRoot%\System32\SyncCenter.dllSigned
{71f96385-ddd6-48d3-a0c1-ae06e8b055fb}
%SystemRoot%\system32\shell32.dllSigned
{73CFD649-CD48-4fd8-A272-2070EA56526B}
C:\Windows\system32\ieframe.dllSigned
{74246bfc-4c96-11d0-abef-0020af6b0b7a}
%SystemRoot%\System32\devmgr.dllSigned
{7444C717-39BF-11D1-8CD9-00C04FC29D45}
%SystemRoot%\system32\cryptext.dllSigned
{7444C719-39BF-11D1-8CD9-00C04FC29D45}
%SystemRoot%\system32\cryptext.dllSigned
{77597368-7b15-11d0-a0c2-080036af3f03}
%systemroot%\system32\printui.dllSigned
{78F3955E-3B90-4184-BD14-5397C15F1EFC}
%SystemRoot%\System32\shdocvw.dllSigned
{7988B573-EC89-11cf-9C00-00AA00A14F56}
dskquoui.dllSigned
{7A0F6AB7-ED84-46B6-B47E-02AA159A152B}
%SystemRoot%\System32\SyncCenter.dllSigned
{7A80E4A8-8005-11D2-BCF8-00C04F72C717}
%SystemRoot%\system32\mmcshext.dllSigned
{7A979262-40CE-46ff-AEEE-7884AC3B6136}
Add New Hardware
{7A9D77BD-5403-11d2-8785-2E0420524153}
User AccountsSigned
{7BA4C742-9E81-11CF-99D3-00AA004AE837}
%SystemRoot%\system32\browseui.dllSigned
{7BD29E00-76C1-11CF-9DD0-00A0C9034933}
C:\Windows\system32\ieframe.dllSigned
{7BD29E01-76C1-11CF-9DD0-00A0C9034933}
C:\Windows\system32\ieframe.dllSigned
{7D4734E6-047E-41e2-AEAA-E763B4739DC4}
%SystemRoot%\system32\wmpshell.dllSigned
{7D559C10-9FE9-11d0-93F7-00AA0059CE02}
C:\Windows\system32\webcheck.dllSigned
{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}
C:\Windows\system32\webcheck.dllSigned
{7b81be6a-ce2b-4676-a29e-eb907a5126c5}
%SystemRoot%\System32\appwiz.cplSigned
{8082C5E6-4C27-48ec-A809-B8E1122E8F97}
%CommonProgramFiles%\System\wab32.dllSigned
{85BBD920-42A0-1069-A2E4-08002B30309D}
syncui.dllSigned
{865e5e76-ad83-4dca-a109-50dc2113ce9a}
%SystemRoot%\system32\shell32.dllSigned
{871C5380-42A0-1069-A2EA-08002B30309D}
C:\Windows\system32\ieframe.dllSigned
{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}
%SystemRoot%\System32\mediametadatahandler.dllSigned
{877ca5ac-cb41-4842-9c69-9136e42d47e2}
%systemroot%\system32\sdshext.dllSigned
{8856f961-340a-11d0-a96b-00c04fd705a2}
C:\Windows\system32\ieframe.dllSigned
{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}
%SystemRoot%\system32\zipfldr.dllSigned
{88C6C381-2E85-11D0-94DE-444553540000}
C:\Windows\system32\occache.dllSigned
{89D83576-6BD1-4c86-9454-BEB04E94C819}
%systemroot%\system32\mssvp.dllSigned
{8A23E65E-31C2-11d0-891C-00A024AB2DBB}
%SystemRoot%\system32\dsquery.dllSigned
{8A734961-C4AA-4741-AC1E-791ACEBF5B39}
%SystemRoot%\system32\wmpshell.dllSigned
{8DD448E6-C188-4aed-AF92-44956194EB1F}
%SystemRoot%\system32\wmpshell.dllSigned
{8E25992B-373E-486E-80E5-BD23AE417E66}
%SystemRoot%\System32\SyncCenter.dllSigned
{8E908FC9-BECC-40f6-915B-F4CA0E70D03D}
%SystemRoot%\System32\shdocvw.dllSigned
{8a7cae0e-5951-49cb-bf20-ab3fa1e44b01}
fontext.dllSigned
{90b9bce2-b6db-4fd3-8451-35917ea1081b}
ExplorerFrame.dllSigned
{90f8c90b-04e0-4e92-a186-e6e9c125d664}
%SystemRoot%\System32\shdocvw.dllSigned
{911051fa-c21c-4246-b470-070cd8df6dc4}
.cab or .zip files
{9113A02D-00A3-46B9-BC5F-9C04DADDD5D7}
%SystemRoot%\system32\EhStorShell.dllSigned
{91ADC906-6722-4B05-A12B-471ADDCCE132}
%SystemRoot%\System32\TouchX.dllSigned
{92337A8C-E11D-11D0-BE48-00C04FC30DF6}
%SystemRoot%\system32\oleprn.dllSigned
{92dbad9f-5025-49b0-9078-2d78f935e341}
%SystemRoot%\system32\inetcomm.dllSigned
{96AE8D84-A250-4520-95A5-A47A7E3C548B}
%SystemRoot%\System32\shdocvw.dllSigned
{97e467b4-98c6-4f19-9588-161b7773d6f6}
%SystemRoot%\system32\propsys.dllSigned
{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8}
C:\Windows\system32\ieframe.dllSigned
{992CFFA0-F557-101A-88EC-00DD010CCC48}
%SystemRoot%\System32\netshell.dllSigned
{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E}
C:\Windows\system32\ieframe.dllSigned
{9C60DE1E-E5FC-40f4-A487-460851A8D915}
%SystemRoot%\System32\shdocvw.dllSigned
{9C73F5E5-7AE7-4E32-A8E8-8D23B85255BF}
%SystemRoot%\System32\SyncCenter.dllSigned
{9D687A4C-1404-41ef-A089-883B6FBECDE6}
"%SystemRoot%\System32\rundll32.exe" "%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dll",ImageView_COMServer {9D687A4C-1404-41ef-A089-883B6FBECDE6}Signed
{9D958C62-3954-4b44-8FAB-C4670C1DB4C2}
C:\Windows\system32\ieframe.dllSigned
{9DBD2C50-62AD-11d0-B806-00C04FD706EC}
%SystemRoot%\system32\shell32.dllSigned
{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}
%SystemRoot%\system32\dsquery.dllSigned
{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}
%SystemRoot%\System32\sendmail.dllSigned
{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}
%SystemRoot%\System32\sendmail.dllSigned
{AB77609F-2178-4E6F-9C4B-44AC179D937A}
C:\Program Files\Emsisoft Anti-Malware\a2contmenu.dllSigned
{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}
C:\Windows\system32\webcheck.dllSigned
{AF4F6510-F982-11d0-8595-00AA004CD6D8}
%SystemRoot%\system32\browseui.dllSigned
{B31C5FAE-961F-415b-BAF0-E697A5178B94}
C:\Windows\system32\ieframe.dllSigned
{B32D3949-ED98-4DBB-B347-17A144969BBA}
%SystemRoot%\System32\SyncCenter.dllSigned
{BB06C0E4-D293-4f75-8A90-CB05B6477EEE}
%SystemRoot%\System32\shdocvw.dllSigned
{BB6B2374-3D79-41DB-87F4-896C91846510}
emdmgmt.dllSigned
{BC476F4C-D9D7-4100-8D4E-E043F6DEC409}
C:\Windows\system32\ieframe.dllSigned
{BC48B32F-5910-47F5-8570-5074A8A5636A}
%SystemRoot%\System32\SyncCenter.dllSigned
{BC65FB43-1958-4349-971A-210290480130}
%SystemRoot%\System32\NcdProp.dllSigned
{BD472F60-27FA-11cf-B8B4-444553540000}
%SystemRoot%\system32\zipfldr.dllSigned
{BD7A2E7B-21CB-41b2-A086-B309680C6B7E}
%systemroot%\system32\mssvp.dllSigned
{BD84B380-8CA2-1069-AB1D-08000948F534}
%SystemRoot%\system32\fontext.dllSigned
{BE122A0E-4503-11DA-8BDE-F66BAD1E3F3A}
%SystemRoot%\System32\shdocvw.dllSigned
{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A}
C:\Windows\system32\ieframe.dllSigned
{C0B4E2F3-BA21-4773-8DBA-335EC946EB8B}
%SystemRoot%\System32\comdlg32.dllSigned
{C4EC38BD-4E9E-4b5e-935A-D1BFF237D980}
%SystemRoot%\system32\browseui.dllSigned
{C73F6F30-97A0-4AD1-A08F-540D4E9BC7B9}
%SystemRoot%\System32\shdocvw.dllSigned
{C7657C4A-9F68-40fa-A4DF-96BC08EB3551}
C:\Windows\system32\PhotoMetadataHandler.dllSigned
{C8494E42-ACDD-4739-B0FB-217361E4894F}
Sam Account Folder
{CB1B7F8C-C50A-4176-B604-9E24DEE8D4D1}
oobefldr.dllSigned
{CC6EEFFB-43F6-46c5-9619-51D571967F7D}
%SystemRoot%\System32\shwebsvc.dllSigned
{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}
%SystemRoot%\system32\wmpshell.dllSigned
{CF67796C-F57F-45F8-92FB-AD698826C602}
%CommonProgramFiles%\System\wab32.dllSigned
{CFBFAE00-17A6-11D0-99CB-00C04FD64497}
C:\Windows\system32\ieframe.dllSigned
{CFCCC7A0-A282-11D1-9082-006008059382}
%SystemRoot%\System32\appwiz.cplSigned
{D20EA4E1-3957-11d2-A40B-0C5020524152}
%SystemRoot%\System32\shdocvw.dllSigned
{D20EA4E1-3957-11d2-A40B-0C5020524153}
%SystemRoot%\System32\shdocvw.dllSigned
{D34A6CA6-62C2-4C34-8A7C-14709C1AD938}
%SystemRoot%\System32\shdocvw.dllSigned
{D555645E-D4F8-4c29-A827-D93C859C4F2A}
%SystemRoot%\System32\shdocvw.dllSigned
{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8}
%SystemRoot%\system32\wpdshext.dllSigned
{DBCE2480-C732-101B-BE72-BA78E9AD5B27}
%SystemRoot%\system32\colorui.dllSigned
{DC1C5A9C-E88A-4dde-A5A1-60F82A20AEF7}
%SystemRoot%\System32\comdlg32.dllSigned
{DD313E04-FEFF-11d1-8ECD-0000F87A470C}
%SystemRoot%\system32\browseui.dllSigned
{DEBB9B79-B3DD-47F4-9E5C-EA6975BAB611}
ReflectShellExt extension
{DFFACDC5-679F-4156-8947-C5C76BC0B67F}
%SystemRoot%\System32\shdocvw.dllSigned
{E29F9716-5C08-4FCD-955A-119FDB5A522D}
Sam Account Folder
{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75}
C:\Windows\system32\dfshim.dllSigned
{E413D040-6788-4C22-957E-175D1C513A34}
%SystemRoot%\System32\SyncCenter.dllSigned
{E44E5D18-0652-4508-A4E2-8A090067BCB0}
Default Programs command object for Start menuSigned
{E598560B-28D5-46aa-A14A-8A3BEA34B576}
%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dllSigned
{E6EE9AAC-F76B-4947-8260-A9F136138E11}
C:\Windows\system32\ieframe.dllSigned
{E6FB5E20-DE35-11CF-9C87-00AA005127ED}
C:\Windows\system32\webcheck.dllSigned
{E7DE9B1A-7533-4556-9484-B26FB486475E}
%SystemRoot%\system32\shdocvw.dllSigned
{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}
C:\Windows\system32\ieframe.dllSigned
{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31}
%SystemRoot%\system32\zipfldr.dllSigned
{E95A4861-D57A-4be1-AD0F-35267E261739}
%SystemRoot%\System32\shdocvw.dllSigned
{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}
DfsShlEx.dllSigned
{ECD4FC4D-521C-11D0-B792-00A0C90312E1}
%SystemRoot%\system32\browseui.dllSigned
{ECD4FC4E-521C-11D0-B792-00A0C90312E1}
%SystemRoot%\system32\browseui.dllSigned
{ECDD6472-2B9B-4b4b-AE36-F316DF3C8D60}
C:\Windows\System32\gameux.dllSigned
{ECF03A32-103D-11d2-854D-006008059367}
%SystemRoot%\system32\mydocs.dllSigned
{ED228FDF-9EA8-4870-83B1-96B02CFE0D52}
C:\Windows\System32\gameux.dllSigned
{ED834ED6-4B5A-4bfe-8F11-A626DCB6A921}
%SystemRoot%\System32\shdocvw.dllSigned
{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}
%SystemRoot%\system32\browseui.dllSigned
{F0152790-D56E-4445-850E-4F3117DB740C}
%SystemRoot%\system32\remotepg.dllSigned
{F020E586-5264-11d1-A532-0000F8757D7E}
%SystemRoot%\system32\dsquery.dllSigned
{F02C1A0D-BE21-4350-88B0-7367FC96EF3C}
%systemroot%\system32\NetworkExplorer.dllSigned
{F04CC277-03A2-4277-96A9-77967471BDFF}
%SystemRoot%\System32\SyncCenter.dllSigned
{F1390A9A-A3F4-4E5D-9C5F-98F3BD8D935C}
%SystemRoot%\System32\SyncCenter.dllSigned
{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}
%SystemRoot%\system32\wmpshell.dllSigned
{F2CF5485-4E02-4f68-819C-B92DE9277049}
C:\Windows\system32\ieframe.dllSigned
{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}
rshx32.dllSigned
{F5175861-2688-11d0-9C5E-00AA00A45957}
C:\Windows\system32\webcheck.dllSigned
{F61FFEC1-754F-11d0-80CA-00AA005B4383}
%SystemRoot%\system32\browseui.dllSigned
{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E}
C:\Windows\system32\ieframe.dllSigned
{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75}
C:\Windows\system32\ieframe.dllSigned
{FBF23B40-E3F0-101B-8488-00AA003E56F8}
C:\Windows\system32\ieframe.dllSigned
{FDE7673D-2E19-4145-8376-BBD58C4BC7BA}
C:\Windows\system32\ieframe.dllSigned
{FF393560-C2A7-11CF-BFF4-444553540000}
C:\Windows\system32\ieframe.dllSigned
{FFE2A43C-56B9-4bf5-9A79-CC6D4285608A}
%ProgramFiles%\Windows Photo Gallery\PhotoViewer.dllSigned
{a304259d-52b8-4526-8b1a-a1d6cecc8243}
iSCSI Initiator
{a38b883c-1682-497e-97b0-0a3a9e801682}
C:\Windows\system32\PhotoMetadataHandler.dllSigned
{a42c2ccb-67d3-46fa-abe6-7d2f3488c7a3}
%SystemRoot%\system32\shell32.dllSigned
{a542e116-8088-4146-a352-b0d06e7f6af6}
%SystemRoot%\system32\browseui.dllSigned
{add36aa8-751a-4579-a266-d66f5202ccbb}
%SystemRoot%\System32\shwebsvc.dllSigned
{b155bdf8-02f0-451e-9a26-ae317cfd7779}
%SystemRoot%\System32\shdocvw.dllSigned
{b2952b16-0e07-4e5a-b993-58c52cb94cae}
%SystemRoot%\system32\shell32.dllSigned
{b2c761c6-29bc-4f19-9251-e6195265baf1}
Color Control Panel AppletSigned
{b8cdcb65-b1bf-4b42-9428-1dfdb7ee92af}
%SystemRoot%\system32\zipfldr.dllSigned
{b9815375-5d7f-4ce2-9245-c9d4da436930}
%SystemRoot%\system32\inetcomm.dllSigned
{c5a40261-cd64-4ccf-84cb-c394da41d590}
%SystemRoot%\System32\mediametadatahandler.dllSigned
{ceefea1b-3e29-4ef1-b34c-fec79c4f70af}
%SystemRoot%\System32\appwiz.cplSigned
{d3e34b21-9d75-101a-8c3d-00aa001a1652}
%systemroot%\system32\mspaint.exeSigned
{d450a8a1-9568-45c7-9c0e-b4f9fb4537bd}
%SystemRoot%\System32\appwiz.cplSigned
{d8559eb9-20c0-410e-beda-7ed416aecc2a}
Windows Defender
{da67b8ad-e81b-4c70-9b91b417b5e33527}
Windows Search Shell Service
{e82a2d71-5b2f-43a0-97b8-81be15854de8}
C:\Windows\system32\dfshim.dllSigned
{eb124705-128b-40d4-8dd8-d93ed12589a4}
%SystemRoot%\System32\shdocvw.dllSigned
{ed50fc29-b964-48a9-afb3-15ebb9b97f36}
%SystemRoot%\System32\shdocvw.dllSigned
{ed9d80b9-d157-457b-9192-0e7280313bf0}
%SystemRoot%\system32\zipfldr.dllSigned
{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}
ntshrui.dllSigned
{f8b8412b-dea3-4130-b36c-5e8be73106ac}
%SystemRoot%\system32\inetcomm.dllSigned
{f92e8c40-3d33-11d2-b1aa-080036a75b03}
deskperf.dllSigned
{fccf70c8-f4d7-4d8b-8c17-cd6715e37fff}
%SystemRoot%\system32\browseui.dllSigned
{fcfeecae-ee1b-4849-ae50-685dcf7717ec}
Problem Reports and Solutions
Explorer\Shell Icon (1 object)
EnhancedStorageShell%SystemRoot%\system32\EhStorShell.dllSigned
Session Manager\KnownDLLs (25 objects)
COMDLG32%SystemRoot%\system32\COMDLG32.dllSigned
IERTUTIL%SystemRoot%\system32\IERTUTIL.dllSigned
IMAGEHLP%SystemRoot%\system32\IMAGEHLP.dllSigned
IMM32%SystemRoot%\system32\IMM32.dllSigned
LPK%SystemRoot%\system32\LPK.dllSigned
MSCTF%SystemRoot%\system32\MSCTF.dllSigned
MSVCRT%SystemRoot%\system32\MSVCRT.dllSigned
NORMALIZ%SystemRoot%\system32\NORMALIZ.dllSigned
NSI%SystemRoot%\system32\NSI.dllSigned
OLEAUT32%SystemRoot%\system32\OLEAUT32.dllSigned
SHELL32%SystemRoot%\system32\SHELL32.dllSigned
SHLWAPI%SystemRoot%\system32\SHLWAPI.dllSigned
Setupapi%SystemRoot%\system32\Setupapi.dllSigned
URLMON%SystemRoot%\system32\URLMON.dllSigned
USP10%SystemRoot%\system32\USP10.dllSigned
WININET%SystemRoot%\system32\WININET.dllSigned
WLDAP32%SystemRoot%\system32\WLDAP32.dllSigned
WS2_32%SystemRoot%\system32\WS2_32.dllSigned
advapi32%SystemRoot%\system32\advapi32.dllSigned
clbcatq%SystemRoot%\system32\clbcatq.dllSigned
gdi32%SystemRoot%\system32\gdi32.dllSigned
kernel32%SystemRoot%\system32\kernel32.dllSigned
ole32%SystemRoot%\system32\ole32.dllSigned
rpcrt4%SystemRoot%\system32\rpcrt4.dllSigned
user32%SystemRoot%\system32\user32.dllSigned
Control Panel\Default (24 objects)
appwiz.cplC:\Windows\System32\appwiz.cplSigned
bthprops.cplC:\Windows\System32\bthprops.cplSigned
collab.cplC:\Windows\System32\collab.cplSigned
desk.cplC:\Windows\System32\desk.cplSigned
DivXControlPanelApplet.cplC:\Windows\System32\DivXControlPanelApplet.cplSigned
Firewall.cplC:\Windows\System32\Firewall.cplSigned
hdwwiz.cplC:\Windows\System32\hdwwiz.cplSigned
inetcpl.cplC:\Windows\System32\inetcpl.cplSigned
infocardcpl.cplC:\Windows\System32\infocardcpl.cplSigned
intl.cplC:\Windows\System32\intl.cplSigned
irprops.cplC:\Windows\System32\irprops.cplSigned
joy.cplC:\Windows\System32\joy.cplSigned
LocalCOM.cplC:\Windows\System32\LocalCOM.cpl
main.cplC:\Windows\System32\main.cplSigned
mmsys.cplC:\Windows\System32\mmsys.cplSigned
ncpa.cplC:\Windows\System32\ncpa.cplSigned
powercfg.cplC:\Windows\System32\powercfg.cplSigned
RTSndMgr.cplC:\Windows\System32\RTSndMgr.cplSigned
sysdm.cplC:\Windows\System32\sysdm.cplSigned
TabletPC.cplC:\Windows\System32\TabletPC.cplSigned
telephon.cplC:\Windows\System32\telephon.cplSigned
timedate.cplC:\Windows\System32\timedate.cplSigned
TOSCDSPD.cplC:\Windows\System32\TOSCDSPD.cpl
wscui.cplC:\Windows\System32\wscui.cplSigned
Control Panel\Cpls (2 objects)
Search Admin%SystemRoot%\System32\srchadmin.dllSigned
Speech%SystemRoot%\System32\Speech\SpeechUX\sapi.cplSigned
Shell Spawning (27 objects)
.bat
batfileSigned
.com
ComFileSigned
.exe
exefileSigned
Applications
"C:\Program Files\Internet Explorer\iexplore.exe" %1Signed
CLSID
"C:\Program Files\Internet Explorer\iexplore.exe"Signed
Drive
%SystemRoot%\Explorer.exeSigned
Folder
%SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%LSigned
Folder
%SystemRoot%\Explorer.exe /separate,/idlist,%I,%LSigned
InternetShortcut
rundll32.exe ieframe.dll,OpenURL %lSigned
Unknown
%SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1Signed
batfile
"%1" %*Signed
comfile
"%1" %*Signed
cplfile
rundll32.exe shell32.dll,Control_RunDLL "%1",%*Signed
exefile
"%1" %*Signed
htafile
C:\Windows\system32\mshta.exe "%1" %*Signed
inffile
%SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1Signed
jsefile
%SystemRoot%\System32\WScript.exe "%1" %*Signed
jsfile
%SystemRoot%\System32\WScript.exe "%1" %*Signed
piffile
"%1" %*Signed
regfile
regedit.exe "%1"Signed
scrfile
"%1"Signed
scrfile
"%1" /SSigned
txtfile
%SystemRoot%\system32\NOTEPAD.EXE %1Signed
vbefile
%SystemRoot%\System32\WScript.exe "%1" %*Signed
vbsfile
%SystemRoot%\System32\WScript.exe "%1" %*Signed
wsffile
"%SystemRoot%\System32\WScript.exe" "%1" %*Signed
wshfile
"%SystemRoot%\System32\WScript.exe" "%1" %*Signed
Up

Network objects

Don't display trusted items

LSP Providers

NameImage PathState
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0642EFCB-8E53-40C6-82BB-3788A1190ACD}] DATAGRAM 5%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{0642EFCB-8E53-40C6-82BB-3788A1190ACD}] SEQPACKET 5%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{427FC2B9-0450-48F8-A590-EBFD0BB7A64C}] DATAGRAM 1%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{427FC2B9-0450-48F8-A590-EBFD0BB7A64C}] SEQPACKET 1%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A8332E4F-D1D9-44E2-9974-27D861DDE347}] DATAGRAM 6%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{A8332E4F-D1D9-44E2-9974-27D861DDE347}] SEQPACKET 6%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B6ADC866-5359-4E36-98D8-22F3A492C77B}] DATAGRAM 2%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{B6ADC866-5359-4E36-98D8-22F3A492C77B}] SEQPACKET 2%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F7132328-D1EE-4FE8-AA4B-7B96B24A5CCB}] DATAGRAM 8%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip6_{F7132328-D1EE-4FE8-AA4B-7B96B24A5CCB}] SEQPACKET 8%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0642EFCB-8E53-40C6-82BB-3788A1190ACD}] DATAGRAM 4%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{0642EFCB-8E53-40C6-82BB-3788A1190ACD}] SEQPACKET 4%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{427FC2B9-0450-48F8-A590-EBFD0BB7A64C}] DATAGRAM 0%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{427FC2B9-0450-48F8-A590-EBFD0BB7A64C}] SEQPACKET 0%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A8332E4F-D1D9-44E2-9974-27D861DDE347}] DATAGRAM 3%SystemRoot%\system32\mswsock.dllSigned
MSAFD NetBIOS [\Device\NetBT_Tcpip_{A8332E4F-D1D9-44E2-9974-27D861DDE347}] SEQPACKET 3%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [RAW/IP]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [RAW/IPv6]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [TCP/IP]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [TCP/IPv6]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [UDP/IP]%SystemRoot%\system32\mswsock.dllSigned
MSAFD Tcpip [UDP/IPv6]%SystemRoot%\system32\mswsock.dllSigned
RSVP TCP Service Provider%SystemRoot%\system32\mswsock.dllSigned
RSVP TCPv6 Service Provider%SystemRoot%\system32\mswsock.dllSigned
RSVP UDP Service Provider%SystemRoot%\system32\mswsock.dllSigned
RSVP UDPv6 Service Provider%SystemRoot%\system32\mswsock.dllSigned
Total:

Hosts\LmHosts Files

Don't display trusted items

Hosts
Hosts file is empty or not present
LmHosts
LmHosts file is empty or not present

Persistent Routes
Network AddressNetmaskGateway AddressMetric
0.0.0.00.0.0.0192.168.1.1-1
Total:
Up

Drivers\Services (from Registry)

Don't display trusted items

Name and DescriptionImage PathStartState
.NET CLR Data
.NET CLR Networking
.NET Data Provider for Oracle
.NET Data Provider for SqlServer
.NETFramework
3qyhufha
\??\C:\Windows\system32\drivers\3qyhufha.sysDEMANDSigned
a2acc
\??\C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sysDEMANDSigned
a2AntiMalware
"C:\Program Files\Emsisoft Anti-Malware\a2service.exe"AUTOSigned
ACPI
system32\drivers\acpi.sysBOOTSigned
adp94xx\SystemRoot\system32\drivers\adp94xx.sysDISABLEDSigned
adpahci\SystemRoot\system32\drivers\adpahci.sysDISABLEDSigned
adpu160m\SystemRoot\system32\drivers\adpu160m.sysDISABLEDSigned
adpu320\SystemRoot\system32\drivers\adpu320.sysDISABLEDSigned
adsi
AeLookupSvc
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
AFD
\SystemRoot\system32\drivers\afd.sysSYSTEMSigned
AgereModemAudio
C:\Windows\system32\agrsmsvc.exeAUTOSigned
AgereSoftModem
system32\DRIVERS\AGRSM.sysDEMANDSigned
agp440
\SystemRoot\system32\drivers\agp440.sysDEMANDSigned
aic78xx\SystemRoot\system32\drivers\djsvs.sysDISABLEDSigned
ALG
%SystemRoot%\System32\alg.exeDEMANDSigned
aliide\SystemRoot\system32\drivers\aliide.sysDISABLEDSigned
amdagp
\SystemRoot\system32\drivers\amdagp.sysDEMANDSigned
amdide\SystemRoot\system32\drivers\amdide.sysDISABLEDSigned
AmdK7
\SystemRoot\system32\drivers\amdk7.sysDISABLEDSigned
AmdK8
system32\DRIVERS\amdk8.sysDEMANDSigned
AntiLog32
\??\C:\Program Files\AntiLogger\AntiLog32.sysSYSTEMSigned
Appinfo
%SystemRoot%\system32\svchost.exe -k netsvcsDEMANDSigned
AppMgmt%SystemRoot%\system32\svchost.exe -k netsvcsSigned
arc\SystemRoot\system32\drivers\arc.sysDISABLEDSigned
arcsas\SystemRoot\system32\drivers\arcsas.sysDISABLEDSigned
AsyncMac
system32\DRIVERS\asyncmac.sysDEMANDSigned
atapi
system32\drivers\atapi.sysBOOTSigned
Ati External Event Utility%SystemRoot%\system32\Ati2evxx.exeAUTOSigned
Atierecord
atikmdagsystem32\DRIVERS\atikmdag.sysDEMANDSigned
AtiPcie
system32\DRIVERS\AtiPcie.sysBOOTSigned
AudioEndpointBuilder
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
Audiosrv
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedAUTOSigned
BattC
Beep
SYSTEM
BFE
%systemroot%\system32\svchost.exe -k LocalServiceNoNetworkAUTOSigned
BITS
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
blbdrive\SystemRoot\system32\drivers\blbdrive.sysDISABLED
bowser
system32\DRIVERS\bowser.sysDEMANDSigned
BrFiltLo
\SystemRoot\system32\drivers\brfiltlo.sysDEMANDSigned
BrFiltUp
\SystemRoot\system32\drivers\brfiltup.sysDEMANDSigned
Browser
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Brserid
\SystemRoot\system32\drivers\brserid.sysDISABLEDSigned
BrSerWdm
\SystemRoot\system32\drivers\brserwdm.sysDISABLEDSigned
BrUsbMdm
\SystemRoot\system32\drivers\brusbmdm.sysDISABLEDSigned
BrUsbSer
\SystemRoot\system32\drivers\brusbser.sysDEMANDSigned
BTHMODEM
\SystemRoot\system32\drivers\bthmodem.sysDISABLEDSigned
BTHPORT
catchme\??\C:\Users\PUNYMI~1\AppData\Local\Temp\catchme.sysDEMAND
cdfs
system32\DRIVERS\cdfs.sysDISABLEDSigned
cdrom
system32\DRIVERS\cdrom.sysSYSTEMSigned
CertPropSvc
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
circlass
system32\DRIVERS\circlass.sysDEMANDSigned
CLFS
System32\CLFS.sysBOOTSigned
clr_optimization_v2.0.50727_32
%systemroot%\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exeDEMANDSigned
CmBatt
system32\DRIVERS\CmBatt.sysDEMANDSigned
cmdide\SystemRoot\system32\drivers\cmdide.sysDISABLEDSigned
Compbatt
system32\DRIVERS\compbatt.sysBOOTSigned
COMSysApp
%SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}DEMANDSigned
crcdisk
system32\drivers\crcdisk.sysBOOTSigned
Crusoe
\SystemRoot\system32\drivers\crusoe.sysDISABLEDSigned
crypt32
CryptSvc
%SystemRoot%\system32\svchost.exe -k NetworkServiceAUTOSigned
CSN5PDTS82
System32\Drivers\CSN5PDTS82.sysSYSTEMSigned
CSN5PDTS82x64
System32\Drivers\CSN5PDTS82x64.sysSYSTEM
DCLocator
DcomLaunch
%SystemRoot%\system32\svchost.exe -k DcomLaunchAUTOSigned
DfsC
System32\Drivers\dfsc.sysSYSTEMSigned
DFSR
%SystemRoot%\system32\DFSR.exeDEMANDSigned
Dhcp
%SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
disk
system32\drivers\disk.sysBOOTSigned
Dnscache
%SystemRoot%\system32\svchost.exe -k NetworkServiceDISABLEDSigned
dot3svc
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedDEMANDSigned
Dot4
system32\DRIVERS\Dot4.sysDEMANDSigned
Dot4Print
system32\DRIVERS\Dot4Prt.sysDEMANDSigned
dot4usb
system32\DRIVERS\dot4usb.sysDEMANDSigned
DPS
%SystemRoot%\System32\svchost.exe -k LocalServiceNoNetworkAUTOSigned
drmkaud
system32\drivers\drmkaud.sysDEMANDSigned
DXGKrnl
\SystemRoot\System32\drivers\dxgkrnl.sysDEMANDSigned
E1G60
system32\DRIVERS\E1G60I32.sysDISABLEDSigned
EapHost
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
Ecache
System32\drivers\ecache.sysBOOTSigned
ehRecvr
%systemroot%\ehome\ehRecvr.exeDEMANDSigned
ehSched
%systemroot%\ehome\ehsched.exeDEMANDSigned
ehstart
%windir%\system32\svchost.exe -k LocalServiceNoNetworkAUTOSigned
elxstor\SystemRoot\system32\drivers\elxstor.sysDISABLEDSigned
EmdCache
EMDMgmt
%systemroot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
ESENT
Eventlog
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedAUTOSigned
EventSystem
%SystemRoot%\system32\svchost.exe -k LocalServiceAUTOSigned
exfat
DEMAND
fastfat
DEMAND
fdc
system32\DRIVERS\fdc.sysDISABLEDSigned
fdPHost
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
FDResPub
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
FileInfo
system32\drivers\fileinfo.sysBOOTSigned
Filetrace
system32\drivers\filetrace.sysDEMANDSigned
flpydisk
system32\DRIVERS\flpydisk.sysDISABLEDSigned
FltMgr
system32\drivers\fltmgr.sysBOOTSigned
FontCache3.0.0.0
%systemroot%\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exeAUTOSigned
Fs_RecSYSTEM
FwLnk
system32\DRIVERS\FwLnk.sysDEMANDSigned
gagp30kx
\SystemRoot\system32\drivers\gagp30kx.sysDEMANDSigned
gpsvc
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
HdAudAddService
system32\drivers\HdAudio.sysDEMANDSigned
HDAudBus
system32\DRIVERS\HDAudBus.sysDEMANDSigned
HidBth
\SystemRoot\system32\drivers\hidbth.sysDISABLEDSigned
HidIr
system32\DRIVERS\hidir.sysDEMANDSigned
hidserv
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
HidUsb
system32\DRIVERS\hidusb.sysDEMANDSigned
hkmsvc
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
HpCISSs\SystemRoot\system32\drivers\hpcisss.sysDISABLEDSigned
HTTP
system32\drivers\HTTP.sysDEMANDSigned
i2omp\SystemRoot\system32\drivers\i2omp.sysDISABLEDSigned
i8042prt
system32\DRIVERS\i8042prt.sysSYSTEMSigned
iaStorV
\SystemRoot\system32\drivers\iastorv.sysDISABLEDSigned
IDriverT
"C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"DEMAND
idsvc
"%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"DEMANDSigned
iirsp\SystemRoot\system32\drivers\iirsp.sysDISABLEDSigned
IKEEXT
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
inetaccs
IntcAzAudAddService
system32\drivers\RTKVHDA.sysDEMANDSigned
intelide\SystemRoot\system32\drivers\intelide.sysDISABLEDSigned
intelppm
system32\DRIVERS\intelppm.sysDISABLEDSigned
IPBusEnum
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedDEMANDSigned
IpFilterDriver
system32\DRIVERS\ipfltdrv.sysDEMANDSigned
iphlpsvc
%SystemRoot%\System32\svchost.exe -k NetSvcsDISABLEDSigned
IPMIDRV\SystemRoot\system32\drivers\ipmidrv.sysDISABLEDSigned
IPNAT
system32\DRIVERS\ipnat.sysDEMANDSigned
IRENUM
system32\drivers\irenum.sysDEMANDSigned
isapnp
\SystemRoot\system32\drivers\isapnp.sysDISABLEDSigned
iScsiPrt
system32\DRIVERS\msiscsi.sysDEMANDSigned
iteatapi
\SystemRoot\system32\drivers\iteatapi.sysDISABLEDSigned
iteraid
\SystemRoot\system32\drivers\iteraid.sysDISABLEDSigned
kbdclass
system32\DRIVERS\kbdclass.sysSYSTEMSigned
kbdhid
system32\DRIVERS\kbdhid.sysSYSTEMSigned
KeyIso
%SystemRoot%\system32\lsass.exeDEMANDSigned
KR10I\SystemRoot\system32\drivers\kr10i.sysDISABLEDSigned
KR10N\SystemRoot\system32\drivers\kr10n.sysDISABLEDSigned
KR3NPXP\SystemRoot\system32\drivers\kr3npxp.sysDISABLED
KSecDDSystem32\Drivers\ksecdd.sysBOOTSigned
KtmRm
%SystemRoot%\System32\svchost.exe -k NetworkServiceAUTOSigned
LanmanServer
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
LanmanWorkstation
%SystemRoot%\System32\svchost.exe -k LocalServiceDISABLEDSigned
ldap
lltdio
system32\DRIVERS\lltdio.sysAUTOSigned
lltdsvc
%SystemRoot%\System32\svchost.exe -k LocalServiceDEMANDSigned
lmhosts
%SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
Lsa
LSI_FC\SystemRoot\system32\drivers\lsi_fc.sysDISABLEDSigned
LSI_SAS\SystemRoot\system32\drivers\lsi_sas.sysDISABLEDSigned
LSI_SCSI\SystemRoot\system32\drivers\lsi_scsi.sysDISABLEDSigned
luafv
\SystemRoot\system32\drivers\luafv.sysAUTOSigned
Mcx2Svc
%SystemRoot%\system32\svchost.exe -k LocalServiceDISABLEDSigned
megasas\SystemRoot\system32\drivers\megasas.sysDISABLEDSigned
MMCSS
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Modemsystem32\drivers\modem.sysDEMANDSigned
monitor
system32\DRIVERS\monitor.sysDEMANDSigned
mouclass
system32\DRIVERS\mouclass.sysSYSTEMSigned
mouhid
system32\DRIVERS\mouhid.sysDEMANDSigned
MountMgr
System32\drivers\mountmgr.sysBOOTSigned
mpio
\SystemRoot\system32\drivers\mpio.sysDISABLEDSigned
mpsdrv
System32\drivers\mpsdrv.sysDEMANDSigned
MpsSvc
%SystemRoot%\system32\svchost.exe -k LocalServiceNoNetworkAUTOSigned
Mraid35x\SystemRoot\system32\drivers\mraid35x.sysDISABLEDSigned
MRxDAV
\SystemRoot\system32\drivers\mrxdav.sysDEMANDSigned
mrxsmb
system32\DRIVERS\mrxsmb.sysDEMANDSigned
mrxsmb10
system32\DRIVERS\mrxsmb10.sysDEMANDSigned
mrxsmb20
system32\DRIVERS\mrxsmb20.sysDEMANDSigned
msahci\SystemRoot\system32\drivers\msahci.sysDISABLEDSigned
msdsm
\SystemRoot\system32\drivers\msdsm.sysDISABLEDSigned
MSDTC
%SystemRoot%\System32\msdtc.exeDEMANDSigned
MSDTC Bridge 3.0.0.0
MsfsSYSTEM
msisadrv
system32\drivers\msisadrv.sysBOOTSigned
MSiSCSI
%systemroot%\system32\svchost.exe -k netsvcsDISABLEDSigned
msiserver
%systemroot%\system32\msiexec.exe /VDEMANDSigned
MSKSSRV
system32\drivers\MSKSSRV.sysDEMANDSigned
MSPCLOCK
system32\drivers\MSPCLOCK.sysDEMANDSigned
MSPQM
system32\drivers\MSPQM.sysDEMANDSigned
MsRPCDEMAND
MSSCNTRS
mssmbios
system32\DRIVERS\mssmbios.sysDEMANDSigned
MSTEE
system32\drivers\MSTEE.sysDEMANDSigned
Mup
System32\Drivers\mup.sysBOOTSigned
napagent
%SystemRoot%\System32\svchost.exe -k NetworkServiceDEMANDSigned
NativeWifiP
system32\DRIVERS\nwifi.sysDEMANDSigned
NDIS
system32\drivers\ndis.sysBOOTSigned
NdisTapi
system32\DRIVERS\ndistapi.sysDEMANDSigned
Ndisuio
system32\DRIVERS\ndisuio.sysDEMANDSigned
NdisWan
system32\DRIVERS\ndiswan.sysDEMANDSigned
NDProxy
DEMAND
Net Driver HPZ12%SystemRoot%\System32\svchost.exe -k HPZ12AUTOSigned
NetBIOS
system32\DRIVERS\netbios.sysSYSTEMSigned
netbt
System32\DRIVERS\netbt.sysSYSTEMSigned
Netlogon
%SystemRoot%\system32\lsass.exeDISABLEDSigned
Netman
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedDEMANDSigned
netprofm
%SystemRoot%\System32\svchost.exe -k LocalServiceAUTOSigned
NetTcpPortSharing
"%systemroot%\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"DISABLEDSigned
nfrd960\SystemRoot\system32\drivers\nfrd960.sysDISABLEDSigned
NlaSvc
%SystemRoot%\System32\svchost.exe -k NetworkServiceAUTOSigned
NpfsSYSTEM
nsi
%systemroot%\system32\svchost.exe -k LocalServiceAUTOSigned
nsiproxy
system32\drivers\nsiproxy.sysSYSTEMSigned
NTDS
NtfsDEMAND
ntrigdigi
\SystemRoot\system32\drivers\ntrigdigi.sysDISABLEDSigned
NullSYSTEM
nvraid\SystemRoot\system32\drivers\nvraid.sysDISABLEDSigned
nvstor\SystemRoot\system32\drivers\nvstor.sysDISABLEDSigned
nv_agp
\SystemRoot\system32\drivers\nv_agp.sysDEMANDSigned
ohci1394
system32\DRIVERS\ohci1394.sysDEMANDSigned
p2pimsvc
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
p2psvc
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
Parport
\SystemRoot\system32\drivers\parport.sysDEMANDSigned
partmgr
System32\drivers\partmgr.sysBOOTSigned
Parvdm\SystemRoot\system32\drivers\parvdm.sysAUTOSigned
PcaSvc
%systemroot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
pci
system32\drivers\pci.sysBOOTSigned
pciidesystem32\drivers\pciide.sysBOOTSigned
pcmcia\SystemRoot\system32\drivers\pcmcia.sysDISABLEDSigned
PEAUTH
system32\drivers\peauth.sysAUTOSigned
PerfDisk
PerfNet
PerfOS
PerfProc
PFNet
C:\Program Files\Privacyware\Privatefirewall 7.0\pfsvc.exeAUTOSigned
pla
%SystemRoot%\System32\svchost.exe -k LocalServiceNoNetworkDEMANDSigned
PlugPlay
%SystemRoot%\system32\svchost.exe -k DcomLaunchAUTOSigned
Pml Driver HPZ12%SystemRoot%\System32\svchost.exe -k HPZ12AUTOSigned
PNRPAutoReg
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
PNRPsvc
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedDISABLEDSigned
PolicyAgent
%SystemRoot%\system32\svchost.exe -k NetworkServiceNetworkRestrictedAUTOSigned
PortProxy
PptpMiniport
system32\DRIVERS\raspptp.sysDEMANDSigned
Processor
\SystemRoot\system32\drivers\processr.sysDISABLEDSigned
ProfSvc
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
ProtectedStorage
%SystemRoot%\system32\lsass.exeDEMANDSigned
PSched
system32\DRIVERS\pacer.sysSYSTEMSigned
pssnap
system32\DRIVERS\pssnap.sysBOOTSigned
pwipf6
system32\DRIVERS\pwipf6.sysSYSTEMSigned
ql2300
\SystemRoot\system32\drivers\ql2300.sysDISABLEDSigned
ql40xx
\SystemRoot\system32\drivers\ql40xx.sysDISABLEDSigned
QWAVE
%windir%\system32\svchost.exe -k LocalServiceDEMANDSigned
QWAVEdrv
\SystemRoot\system32\drivers\qwavedrv.sysDEMANDSigned
RasAcd
System32\DRIVERS\rasacd.sysSYSTEMSigned
RasAuto
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
Rasl2tp
system32\DRIVERS\rasl2tp.sysDEMANDSigned
RasMan
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
RasPppoe
system32\DRIVERS\raspppoe.sysDEMANDSigned
RasSstp
system32\DRIVERS\rassstp.sysDEMANDSigned
rdbss
system32\DRIVERS\rdbss.sysSYSTEMSigned
RDPCDD
System32\DRIVERS\RDPCDD.sysSYSTEMSigned
RDPDD
rdpdr
\SystemRoot\system32\drivers\rdpdr.sysDISABLEDSigned
RDPENCDD
system32\drivers\rdpencdd.sysSYSTEMSigned
RDPNP
RDPWD
DEMAND
ReflectService
"C:\Program Files\Macrium\Reflect\ReflectService.exe"AUTOSigned
RemoteAccess
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
RemoteRegistry
%SystemRoot%\system32\svchost.exe -k regsvcDISABLEDSigned
rimmptsksystem32\DRIVERS\rimmptsk.sysAUTOSigned
rimsptsksystem32\DRIVERS\rimsptsk.sysAUTOSigned
rismxdp
system32\DRIVERS\rixdptsk.sysAUTOSigned
RpcLocator
%SystemRoot%\system32\locator.exeDEMANDSigned
RpcSs
%SystemRoot%\system32\svchost.exe -k rpcssAUTOSigned
rspndr
system32\DRIVERS\rspndr.sysAUTOSigned
RTL8169
system32\DRIVERS\Rtlh86.sysDEMANDSigned
RTL8187B
system32\DRIVERS\RTL8187B.sysDEMANDSigned
SamSs
%SystemRoot%\system32\lsass.exeAUTOSigned
SbieDrv
\??\C:\Program Files\Sandboxie\SbieDrv.sysDEMANDSigned
SbieSvc
"C:\Program Files\Sandboxie\SbieSvc.exe"AUTOSigned
sbp2port
\SystemRoot\system32\drivers\sbp2port.sysDISABLEDSigned
SBRE\??\C:\Windows\system32\drivers\SBREdrv.sysSYSTEMSigned
SCardSvr
%SystemRoot%\system32\svchost.exe -k LocalServiceDISABLEDSigned
Schedule
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
SCPolicySvc
%SystemRoot%\system32\svchost.exe -k netsvcsDISABLEDSigned
sdbussystem32\DRIVERS\sdbus.sysDEMANDSigned
SDRSVC
%SystemRoot%\system32\svchost.exe -k SDRSVCDEMANDSigned
secdrv
AUTO
seclogon
%windir%\system32\svchost.exe -k netsvcsAUTOSigned
SENS
%SystemRoot%\system32\svchost.exe -k netsvcsAUTOSigned
Serenum
\SystemRoot\system32\drivers\serenum.sysDEMANDSigned
Serial
\SystemRoot\system32\drivers\serial.sysDEMANDSigned
sermouse
\SystemRoot\system32\drivers\sermouse.sysDISABLEDSigned
ServiceModelEndpoint 3.0.0.0
ServiceModelOperation 3.0.0.0
ServiceModelService 3.0.0.0
SessionEnv
%SystemRoot%\System32\svchost.exe -k netsvcsDISABLEDSigned
sffdisk
\SystemRoot\system32\drivers\sffdisk.sysDISABLEDSigned
sffp_mmc
\SystemRoot\system32\drivers\sffp_mmc.sysDEMANDSigned
sffp_sd
\SystemRoot\system32\drivers\sffp_sd.sysDEMANDSigned
sfloppy
\SystemRoot\system32\drivers\sfloppy.sysDISABLEDSigned
SharedAccess
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
ShellHWDetection
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
sisagp
\SystemRoot\system32\drivers\sisagp.sysDEMANDSigned
SiSRaid2\SystemRoot\system32\drivers\sisraid2.sysDISABLEDSigned
SiSRaid4\SystemRoot\system32\drivers\sisraid4.sysDISABLEDSigned
slsvc
%SystemRoot%\system32\SLsvc.exeAUTOSigned
SLUINotify
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
Smb
system32\DRIVERS\smb.sysSYSTEMSigned
SMSvcHost 3.0.0.0
SNARE
C:\Program Files\Snare\SnareCore.EXEAUTO
SNMPTRAP
%SystemRoot%\System32\snmptrap.exeDISABLEDSigned
spldr
BOOT
Spooler
%SystemRoot%\System32\spoolsv.exeAUTOSigned
srvSystem32\DRIVERS\srv.sysDEMANDSigned
srv2
System32\DRIVERS\srv2.sysDEMANDSigned
srvnetSystem32\DRIVERS\srvnet.sysDEMANDSigned
SSDPSRV
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
SstpSvc
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
stisvc
%SystemRoot%\system32\svchost.exe -k imgsvcAUTOSigned
swenum
system32\DRIVERS\swenum.sysDEMANDSigned
swprv
%SystemRoot%\System32\svchost.exe -k swprvDEMANDSigned
Symc8xx\SystemRoot\system32\drivers\symc8xx.sysDISABLEDSigned
Sym_hi\SystemRoot\system32\drivers\sym_hi.sysDISABLEDSigned
Sym_u3\SystemRoot\system32\drivers\sym_u3.sysDISABLEDSigned
SynTP
system32\DRIVERS\SynTP.sysDEMANDSigned
SysMain
%systemroot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
TabletInputService
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedDISABLEDSigned
TapiSrv
%SystemRoot%\System32\svchost.exe -k NetworkServiceDEMANDSigned
TBS
%SystemRoot%\System32\svchost.exe -k LocalServiceAUTOSigned
Tcpip
System32\drivers\tcpip.sysBOOTSigned
Tcpip6
system32\DRIVERS\tcpip.sysDEMANDSigned
tcpipreg
System32\drivers\tcpipreg.sysAUTOSigned
tdcmdpst
system32\DRIVERS\tdcmdpst.sysDEMANDSigned
TDPIPE
system32\drivers\tdpipe.sysDEMANDSigned
TDTCP
system32\drivers\tdtcp.sysDEMANDSigned
tdx
system32\DRIVERS\tdx.sysSYSTEMSigned
TermDD
system32\DRIVERS\termdd.sysSYSTEMSigned
TermService
%SystemRoot%\System32\svchost.exe -k NetworkServiceDISABLEDSigned
Themes
%SystemRoot%\System32\svchost.exe -k netsvcsAUTOSigned
THREADORDER
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
TNaviSrv
C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exeAUTO
TODDSrv
C:\Windows\system32\TODDSrv.exeAUTO
TOSHIBA Bluetooth Service
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exeAUTOSigned
tosrfec
system32\DRIVERS\tosrfec.sysDEMANDSigned
Tosrfusb
tos_sps32
system32\DRIVERS\tos_sps32.sysBOOTSigned
TrkWks
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedDISABLEDSigned
TrustedInstaller
%SystemRoot%\servicing\TrustedInstaller.exeDEMANDSigned
TSDDD
tssecsrv
System32\DRIVERS\tssecsrv.sysDEMANDSigned
tunnel
system32\DRIVERS\tunnel.sysDEMANDSigned
TVALZ
system32\DRIVERS\TVALZ_O.SYSBOOTSigned
uagp35
\SystemRoot\system32\drivers\uagp35.sysDEMANDSigned
udfs
system32\DRIVERS\udfs.sysDISABLEDSigned
UGatherer
UGTHRSVC
UI0Detect
%SystemRoot%\system32\UI0Detect.exeDEMANDSigned
UleadBurningHelper
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exeAUTO
uliagpkx
\SystemRoot\system32\drivers\uliagpkx.sysDEMANDSigned
uliahci\SystemRoot\system32\drivers\uliahci.sysDISABLEDSigned
UlSata\SystemRoot\system32\drivers\ulsata.sysDISABLEDSigned
ulsata2\SystemRoot\system32\drivers\ulsata2.sysDISABLEDSigned
umbus
system32\DRIVERS\umbus.sysDEMANDSigned
upnphost
%SystemRoot%\system32\svchost.exe -k LocalServiceDEMANDSigned
usb
usbccgp
system32\DRIVERS\usbccgp.sysDEMANDSigned
usbcir
\SystemRoot\system32\drivers\usbcir.sysDISABLEDSigned
usbehci
system32\DRIVERS\usbehci.sysDEMANDSigned
usbhub
system32\DRIVERS\usbhub.sysDEMANDSigned
usbohci
system32\DRIVERS\usbohci.sysDEMANDSigned
usbprint
system32\DRIVERS\usbprint.sysDEMANDSigned
usbscan
system32\DRIVERS\usbscan.sysDEMANDSigned
USBSTOR
system32\DRIVERS\USBSTOR.SYSDEMANDSigned
usbuhci
system32\DRIVERS\usbuhci.sysDISABLEDSigned
usbvideo
System32\Drivers\usbvideo.sysDEMANDSigned
UxSms
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
VBoxDrv
system32\DRIVERS\VBoxDrv.sysSYSTEMSigned
VBoxNetAdp
system32\DRIVERS\VBoxNetAdp.sysDEMANDSigned
VBoxNetFlt
system32\DRIVERS\VBoxNetFlt.sysDEMANDSigned
VBoxUSBMon
system32\DRIVERS\VBoxUSBMon.sysSYSTEMSigned
vds
%SystemRoot%\System32\vds.exeDEMANDSigned
vgasystem32\DRIVERS\vgapnp.sysDEMANDSigned
VgaSave\SystemRoot\System32\drivers\vga.sysSYSTEMSigned
viaagp
\SystemRoot\system32\drivers\viaagp.sysDEMANDSigned
ViaC7
\SystemRoot\system32\drivers\viac7.sysDISABLEDSigned
viaide\SystemRoot\system32\drivers\viaide.sysDISABLEDSigned
volmgr
system32\drivers\volmgr.sysBOOTSigned
volmgrx
System32\drivers\volmgrx.sysBOOTSigned
volsnap
system32\drivers\volsnap.sysBOOTSigned
vsmraid\SystemRoot\system32\drivers\vsmraid.sysDISABLEDSigned
VSS
%systemroot%\system32\vssvc.exeDEMANDSigned
W32Time
%SystemRoot%\system32\svchost.exe -k LocalServiceAUTOSigned
W3SVC
WacomPen
\SystemRoot\system32\drivers\wacompen.sysDISABLEDSigned
Wanarp
system32\DRIVERS\wanarp.sysDEMANDSigned
Wanarpv6
system32\DRIVERS\wanarp.sysSYSTEMSigned
wcncsvc
%SystemRoot%\System32\svchost.exe -k LocalServiceDEMANDSigned
WcsPlugInService
%SystemRoot%\system32\svchost.exe -k wcssvcDEMANDSigned
Wd
\SystemRoot\system32\drivers\wd.sysDISABLEDSigned
Wdf01000
system32\drivers\Wdf01000.sysBOOTSigned
WdiServiceHost
%SystemRoot%\System32\svchost.exe -k wdisvcDEMANDSigned
WdiSystemHost
%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestrictedDEMANDSigned
WebClient
%SystemRoot%\system32\svchost.exe -k LocalServiceDISABLEDSigned
Wecsvc
%SystemRoot%\system32\svchost.exe -k NetworkServiceDEMANDSigned
wercplsupport
%SystemRoot%\System32\svchost.exe -k netsvcsDEMANDSigned
WerSvc
%SystemRoot%\System32\svchost.exe -k WerSvcGroupAUTOSigned
winbondcir
system32\DRIVERS\winbondcir.sysDEMANDSigned
WinDefend
%SystemRoot%\System32\svchost.exe -k secsvcsAUTOSigned
Windows Workflow Foundation 3.0.0.0
WinHttpAutoProxySvc
%SystemRoot%\system32\svchost.exe -k LocalServiceDISABLEDSigned
Winmgmt
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
WinRM
%SystemRoot%\System32\svchost.exe -k NetworkServiceDISABLEDSigned
WinsockDEMAND
WinSock2
Wlansvc
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
WmiAcpi
\SystemRoot\system32\drivers\wmiacpi.sysDISABLEDSigned
WmiApRpl
wmiApSrv
%systemroot%\system32\wbem\WmiApSrv.exeDEMANDSigned
WMPNetworkSvc
"%ProgramFiles%\Windows Media Player\wmpnetwk.exe"DISABLEDSigned
WPCSvc
%SystemRoot%\system32\svchost.exe -k LocalServiceNetworkRestrictedDEMANDSigned
WPDBusEnum
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
ws2ifsl
\SystemRoot\system32\drivers\ws2ifsl.sysDISABLEDSigned
wscsvc
%SystemRoot%\System32\svchost.exe -k LocalServiceNetworkRestrictedAUTOSigned
WSearch
%systemroot%\system32\SearchIndexer.exe /EmbeddingDISABLEDSigned
WSearchIdxPi
wuauserv
%systemroot%\system32\svchost.exe -k netsvcsAUTOSigned
WUDFRdsystem32\DRIVERS\WUDFRd.sysDEMANDSigned
wudfsvc
%SystemRoot%\system32\svchost.exe -k LocalSystemNetworkRestrictedAUTOSigned
xmlprov
{0642EFCB-8E53-40C6-82BB-3788A1190ACD}
{427FC2B9-0450-48F8-A590-EBFD0BB7A64C}
{A8332E4F-D1D9-44E2-9974-27D861DDE347}
Total:
Up

Log generation finished: 19-03-2011 18:33:50
Time spent: 00:21:08

Copyright © 1993-2011 VirusBlokAda Ltd. All rights reserved.