GMER 1.0.15.14972 -
http://www.gmer.netRootkit scan 2009-07-12 15:58:05
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.15 ----
Code 8A442378 ZwEnumerateKey
Code 897F9718 ZwFlushInstructionCache
Code 8A2EFC2F IoDeleteDevice
Code 8A65358F IoRegisterDeviceInterface
Code 8A650317 IoSetDeviceInterfaceState
Code 897F29BE IofCallDriver
Code 897FB4EE IofCompleteRequest
Code DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.) PsDisableImpersonation
Code DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.) PsImpersonateClient
Code DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.) PsRestoreImpersonation
Code DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.) PsRevertThreadToSelf
Code DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.) PsRevertToSelf
---- Kernel code sections - GMER 1.0.15 ----
.text ntkrnlpa.exe!IofCallDriver 804EF0BC 5 Bytes JMP 897F29C3
.text ntkrnlpa.exe!IofCompleteRequest 804EF14C 5 Bytes JMP 897FB4F3
.text ntkrnlpa.exe!IoDeleteDevice 804F1808 5 Bytes JMP 8A2EFC34
PAGE ntkrnlpa.exe!IoSetDeviceInterfaceState 805877E8 5 Bytes JMP 8A65031C
PAGE ntkrnlpa.exe!IoRegisterDeviceInterface 80587924 5 Bytes JMP 8A653594
PAGE ntkrnlpa.exe!ZwFlushInstructionCache 805B528A 5 Bytes JMP 897F971C
PAGE ntkrnlpa.exe!PsImpersonateClient 805CD9A0 5 Bytes JMP B9EC82AA DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.)
PAGE ntkrnlpa.exe!PsDisableImpersonation 805CDC62 5 Bytes JMP B9EC8372 DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.)
PAGE ntkrnlpa.exe!PsRestoreImpersonation 805CDD3A 5 Bytes JMP B9EC8406 DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.)
PAGE ntkrnlpa.exe!PsRevertToSelf 805CDD6E 5 Bytes JMP B9EC8544 DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.)
PAGE ntkrnlpa.exe!PsRevertThreadToSelf 805CDDFE 5 Bytes JMP B9EC84C0 DGMaster.sys (Digital Guardian Agent Master for 2K/XP/Verdasys, Inc.)
PAGE ntkrnlpa.exe!ZwEnumerateKey 8062296E 5 Bytes JMP 8A44237C
PAGE fltmgr.sys!FltLoadFilter + 25E B9E14B92 5 Bytes JMP 89DD07EC
.text NDIS.sys!NdisCompleteBindAdapter B9C8FA44 5 Bytes JMP 8A2ECFCC
PAGENPNP NDIS.sys!NdisRegisterProtocol B9C9617D 5 Bytes JMP 8A2F5D8C
PAGENPNP NDIS.sys!NdisDeregisterProtocol B9CA07FD 5 Bytes JMP 8A2FA2E4
PAGENDSP NDIS.sys!NdisMWanSendComplete + FE2 B9CA624F 5 Bytes JMP 8A49AC14
PAGENDSP NDIS.sys!NdisReset + B7 B9CA6A8F 5 Bytes JMP 8A4A656C
.text tcpip.sys!ARPRcvPacket A7F397FA 5 Bytes JMP 8A49C8B4
.text tcpip.sys!ARPRcv A7F3E2A0 5 Bytes JMP 8A49C7BC
.text tcpip.sys!ARPRcv + AF1 A7F3ED91 5 Bytes JMP 8A43E46C
.text tcpip.sys!ARPRcv + D10 A7F3EFB0 5 Bytes JMP 8A545CC4
.text tcpip.sys!ARPRcv + 3250 A7F414F0 5 Bytes JMP 8A494C14
.text tcpip.sys!IPGetInfo + AAF A7F50C73 5 Bytes JMP 8A49950C
.text tcpip.sys!IPDelayedNdisReEnumerateBindings + 70D A7F5317D 5 Bytes JMP 8A2F0924
.text tcpip.sys!tcpxsum + 11128 A7F671BE 5 Bytes JMP 8A49BA94
.text tcpip.sys!tcpxsum + 11673 A7F67709 5 Bytes JMP 8A49AB1C
.text tcpip.sys!tcpxsum + 11793 A7F67829 5 Bytes JMP 8A497F34
? system32\drivers\yswff.sys The system cannot find the path specified. !
? \DmkServer\??\WINDOWS\System32\ntdll.dll The system cannot find the path specified. !
---- User code sections - GMER 1.0.15 ----
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 006B000A
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\DGAgent\DgService.exe[692] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0097000A
.text C:\WINDOWS\System32\SCardSvr.exe[728] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0064000A
.text C:\WINDOWS\System32\SCardSvr.exe[728] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\SCardSvr.exe[728] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 006C000A
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\crypserv.exe[756] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\NOTEPAD.EXE[812] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 008C000A
.text C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe[1056] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0093000A
.text C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe[1388] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 006A000A
.text C:\Program Files\WebEx\Productivity Tools\ptSrv.exe[1432] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 088F000A
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] netapi32.dll!NetShareAdd 5B86FD48 7 Bytes JMP 7803BA2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] netapi32.dll!NetShareSetInfo 5B8710C4 7 Bytes JMP 7803BA60 C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe[1560] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0071000A
.text C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe[1612] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 007B000A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 00B8000A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] NETAPI32.dll!NetShareAdd 5B86FD48 7 Bytes JMP 7803BA2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] NETAPI32.dll!NetShareSetInfo 5B8710C4 7 Bytes JMP 7803BA60 C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\winlogon.exe[1900] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0065000A
.text C:\WINDOWS\system32\services.exe[1944] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0064000A
.text C:\WINDOWS\System32\svchost.exe[2092] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0065000A
.text C:\WINDOWS\system32\NOTEPAD.EXE[2224] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 008C000A
.text C:\WINDOWS\System32\svchost.exe[2260] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0065000A
.text ...
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] NETAPI32.dll!NetShareAdd 5B86FD48 7 Bytes JMP 7803BA2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] NETAPI32.dll!NetShareSetInfo 5B8710C4 7 Bytes JMP 7803BA60 C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\locator.exe[2860] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\Program Files\LANDesk\LDClient\softmon.exe[2900] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0091000A
.text C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe[2932] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 009B000A
.text C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe[3200] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 003E000A
.text C:\WINDOWS\system32\hkcmd.exe[3296] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0899000A
.text C:\WINDOWS\system32\igfxpers.exe[3304] ntdll.dll!LdrLoadDll 7C915CBB 3 Bytes JMP 0892000A
.text ...
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!OpenServiceW 77DE5F05 5 Bytes JMP 7804402C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!EnumServicesStatusA 77DED89F 5 Bytes JMP 78043BAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!ControlService 77DEE055 5 Bytes JMP 78043AEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!OpenServiceA 77DEE2AE 5 Bytes JMP 78043F6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!EnumServicesStatusExW 77E36863 3 Bytes JMP 78043DEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!EnumServicesStatusExW + 4 77E36867 1 Byte [00]
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!EnumServicesStatusExA 77E36AD7 5 Bytes JMP 78043D2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] ADVAPI32.dll!UnlockServiceDatabase + 73 77E37C04 7 Bytes JMP 78043C6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] GDI32.dll!DeleteDC + 115 77F16F74 7 Bytes JMP 7800D20C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] USER32.dll!GetWindowRgnBox + 97 7E41FC20 7 Bytes JMP 7801A47C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] USER32.dll!CreateWindowExW + 309 7E41FF2E 7 Bytes JMP 7801A3BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] SHELL32.dll!SHCreateDirectoryExA + 5F21 7CA6FDE9 7 Bytes JMP 7801277C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] SHELL32.dll!SHFileOperationW + 2E3 7CA700D1 7 Bytes JMP 780126BC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WININET.dll!InternetLockRequestFile + 25E8 771CE9A4 7 Bytes JMP 7804EECC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 7804920C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!select 71AB2DC0 5 Bytes JMP 7804892C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!connect 71AB406A 5 Bytes JMP 780487AC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!send 71AB428A 5 Bytes JMP 780489EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSARecv 71AB4318 5 Bytes JMP 78048DAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSAEnumNetworkEvents 71AB4617 5 Bytes JMP 78048CEC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!gethostbyname 71AB4FD4 5 Bytes JMP 780492CC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!recv 71AB615A 5 Bytes JMP 7804886C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSASend 71AB6233 5 Bytes JMP 78048E6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!closesocket 71AB9639 5 Bytes JMP 780486EC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSAAsyncSelect 71AC0979 5 Bytes JMP 78048B6C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSAConnect 71AC0C69 5 Bytes JMP 78048C2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] WS2_32.dll!WSAAccept 71AC0DA9 5 Bytes JMP 78048AAC C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] NETAPI32.dll!NetShareAdd 5B86FD48 7 Bytes JMP 7803BA2C C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\System32\wbem\unsecapp.exe[3368] NETAPI32.dll!NetShareSetInfo 5B8710C4 7 Bytes JMP 7803BA60 C:\WINDOWS\System32\DgApi.dll (DgApiMon Dynamic Link Library/Verdasys, Inc.)
.text C:\WINDOWS\system32\wbem\wmiprvse.exe[3460] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0076000A
.text C:\Program Files\LANDesk\LDClient\webportal\sdclientmonitor.exe[3564] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 008F000A
.text C:\Program Files\WebEx\Productivity Tools\PTIM.exe[3568] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0093000A
.text C:\Program Files\WebEx\Productivity Tools\ptmsgfrm.exe[3588] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0091000A
.text C:\WINDOWS\system32\wuauclt.exe[3592] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 003B000A
.text ...
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!GetWindowLongW 7E4188A6 5 Bytes JMP 0033F817 C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!SetScrollInfo 7E419056 5 Bytes JMP 0033FA2A C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!GetWindowLongA 7E41945D 5 Bytes JMP 0033F760 C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!SetWindowLongA 7E41D60D 5 Bytes JMP 0033F57E C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!SetWindowLongW 7E41D62B 5 Bytes JMP 0033F67C C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!GetScrollInfo 7E420DA2 5 Bytes JMP 0033F962 C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!SetScrollPos 7E42F710 5 Bytes JMP 0033FB31 C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\Program Files\WebEx\Productivity Tools\ptoneclk.exe[3628] USER32.dll!SetScrollRange 7E42F95B 5 Bytes JMP 0033FC38 C:\Program Files\WebEx\Productivity Tools\ptSknMgr.dll (WebEx One-Click atsknmgr/WebEx Communications Inc.)
.text C:\WINDOWS\system32\AESTFltr.exe[3696] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0098000A
.text C:\Program Files\IDT\WDM\sttray.exe[3704] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 009B000A
.text C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe[3728] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 003E000A
.text C:\Program Files\DGAgent\DgScan.exe[3816] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 0093000A
.text C:\Documents and Settings\sfratian\Desktop\o0qzvldl.exe[3956] ntdll.dll!LdrLoadDll 7C915CBB 5 Bytes JMP 089B000A
---- User IAT/EAT - GMER 1.0.15 ----
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 009A0078
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 009A009C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 009A009C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 009A00E4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 009A00C0
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 009A0174
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 009A0468
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 009A0228
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 009A03D8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 009A024C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 009A0348
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 009A0030
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 009A000C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 009A0054
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 009A0078
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 009A009C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 009A0468
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 009A03D8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 009A02DC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 009A0348
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 009A0174
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 009A03D8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 009A0348
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 009A0390
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 009A0468
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 009A02DC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 009A03D8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 009A0468
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 009A0078
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 009A009C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 009A03B4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 009A0468
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 009A024C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 009A0444
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 009A0300
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 009A0174
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 009A00C0
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 009A00E4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 009A03B4
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 009A048C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 009A036C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 009A024C
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 009A03FC
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 009A02B8
IAT c:\program files\idt\dellxpm09b_6124v037\wdm\stacsv.exe[316] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 009A04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 008E0468
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 008E0228
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 008E03D8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 008E024C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 008E0348
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 008E0078
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 008E009C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 008E009C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 008E00E4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 008E00C0
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 008E0174
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 008E0078
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 008E009C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 008E03B4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 008E0468
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 008E024C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 008E0444
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 008E0300
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 008E0174
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 008E00C0
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 008E00E4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 008E0030
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 008E000C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 008E0054
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 008E0078
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 008E009C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 008E0468
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 008E03D8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 008E02DC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 008E0348
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 008E0174
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 008E03B4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 008E036C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 008E024C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 008E02B8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 008E03D8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 008E0348
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 008E0390
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 008E0468
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 008E02DC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 008E03D8
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 008E03FC
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 008E0468
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 008E048C
IAT C:\WINDOWS\System32\SCardSvr.exe[728] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 008E04D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 00770078
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 0077009C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 007703B4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 00770468
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 0077024C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 00770444
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 00770300
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 00770174
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 007700C0
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 007700E4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 00770078
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 0077009C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 00770468
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 00770228
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 007703D8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 0077024C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 00770348
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 00770030
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 0077000C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 00770054
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 00770078
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 0077009C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 00770468
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 007703D8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 007702DC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 00770348
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 00770174
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 007703D8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 00770348
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 00770390
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 00770468
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 007702DC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 007703D8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 00770468
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 0077009C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 007700E4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 007700C0
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 00770174
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 007703B4
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 0077048C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 0077036C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 0077024C
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 007703FC
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 007702B8
IAT C:\WINDOWS\system32\crypserv.exe[756] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 007704D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 01220468
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 01220228
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 012203D8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 0122024C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 01220348
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 01220078
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 0122009C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 0122009C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 012200E4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 012200C0
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 01220174
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 01220030
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 0122000C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 01220054
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 01220078
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 0122009C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 01220468
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 012203D8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 012202DC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 01220348
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 01220174
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 01220078
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 0122009C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 012203B4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 01220468
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 0122024C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 01220444
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 01220300
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 01220174
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 012200C0
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 012200E4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 012203D8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 01220348
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 01220390
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 01220468
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 012202DC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 012203D8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 01220468
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!MoveFileExW] 012203B4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!SetEnvironmentVariableW] 0122024C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!CopyFileW] 012202B8
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\userenv.dll [KERNEL32.dll!GetFileAttributesExW] 012204D4
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!GetFileAttributesW] 0122048C
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!DeleteFileW] 012203FC
IAT C:\Program Files\Common Files\Symantec Shared\ccProxy.exe[1548] @ C:\WINDOWS\system32\netapi32.dll [KERNEL32.dll!MoveFileW] 0122036C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 09470078
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 0947009C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 09470078
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 0947009C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 09470444
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 094704F8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 094702DC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 094704D4
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 09470390
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 09470174
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 094700C0
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 094700E4
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 094704F8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 094702B8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 09470468
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 094702DC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 094703D8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 09470030
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 0947000C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 09470054
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 09470078
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 0947009C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 094704F8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 09470468
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 0947036C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 094703D8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 09470174
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 09470468
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 094704F8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 0947009C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 094700E4
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 094700C0
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 09470174
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 09470468
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 094703D8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 09470420
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 094704F8
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 0947036C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 09470444
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 094702DC
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 09470348
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 09470564
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0947051C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!DeleteFileW] 0947048C
IAT C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe[1800] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!MoveFileW] 094703FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 00860468
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 00860228
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 008603D8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 0086024C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 00860348
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 00860078
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 0086009C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 0086009C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 008600E4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 008600C0
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 00860174
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 00860078
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 0086009C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 008603B4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 00860468
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 0086024C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 00860444
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 00860300
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 00860174
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 008600C0
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 008600E4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 00860030
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 0086000C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 00860054
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 00860078
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 0086009C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 00860468
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 008603D8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 008602DC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 00860348
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 00860174
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 008603B4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 0086036C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 0086024C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 008602B8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 008603D8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 00860348
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 00860390
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 00860468
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 008602DC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 008603D8
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 008603FC
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 00860468
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 0086048C
IAT C:\WINDOWS\System32\locator.exe[2860] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 008604D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesA] 00F80468
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableA] 00F80228
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileA] 00F803D8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!SetEnvironmentVariableW] 00F8024C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\msvcrt.dll [KERNEL32.dll!MoveFileA] 00F80348
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ADVAPI32.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\GDI32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!CreateDCW] 00F80078
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USER32.dll [GDI32.dll!DeleteDC] 00F8009C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USER32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [GDI32.dll!DeleteDC] 00F8009C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!GetClipboardData] 00F800E4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!SetClipboardData] 00F800C0
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\ole32.dll [USER32.dll!DispatchMessageW] 00F80174
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!CreateDCW] 00F80078
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [GDI32.dll!DeleteDC] 00F8009C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileExW] 00F803B4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesA] 00F80468
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!SetEnvironmentVariableW] 00F8024C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!MoveFileWithProgressW] 00F80444
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!CopyFileExW] 00F80300
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!DispatchMessageW] 00F80174
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!SetClipboardData] 00F800C0
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHELL32.dll [USER32.dll!GetClipboardData] 00F800E4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocA] 00F80030
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!StartDocW] 00F8000C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCA] 00F80054
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!CreateDCW] 00F80078
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [GDI32.dll!DeleteDC] 00F8009C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesA] 00F80468
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileA] 00F803D8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileA] 00F802DC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileA] 00F80348
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\SHLWAPI.dll [USER32.dll!DispatchMessageW] 00F80174
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] 00F803B4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!MoveFileW] 00F8036C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!SetEnvironmentVariableW] 00F8024C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!CopyFileW] 00F802B8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\USERENV.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!DeleteFileA] 00F803D8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileA] 00F80348
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!MoveFileExA] 00F80390
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!GetFileAttributesA] 00F80468
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\WININET.dll [KERNEL32.dll!CopyFileA] 00F802DC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileA] 00F803D8
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesA] 00F80468
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\CRYPT32.dll [KERNEL32.dll!GetFileAttributesExW] 00F804D4
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!GetFileAttributesW] 00F8048C
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!DeleteFileW] 00F803FC
IAT C:\WINDOWS\System32\wbem\unsecapp.exe[3368] @ C:\WINDOWS\system32\NETAPI32.dll [KERNEL32.dll!MoveFileW] 00F8036C
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs DGFSMon.SYS (Digital Guardian Agent File System Filter for 2K/XP/Verdasys, Inc.)
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
Device \Driver\Tcpip \Device\Ip Code 8A43E468
Device \Driver\Tcpip \Device\Ip Code 8A545CC0
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip Lbd.sys (Boot Driver/Lavasoft AB)
Device \FileSystem\Lbd \Device\Lbd Code 8A338BA0
Device \FileSystem\Lbd \Device\Lbd Code 893D61C8
Device \FileSystem\Lbd \Device\Lbd Code 8A2FF968
Device \Driver\Tcpip \Device\Tcp Code 8A43E468
Device \Driver\Tcpip \Device\Tcp Code 8A545CC0
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp Lbd.sys (Boot Driver/Lavasoft AB)
Device \Driver\Ftdisk \Device\HarddiskVolume1 DGBusMon.SYS (Digital Guardian Agent Bus Filter for 2K/XP/Verdasys, Inc.)
Device \Driver\Tcpip \Device\Udp Code 8A43E468
Device \Driver\Tcpip \Device\Udp Code 8A545CC0
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp Lbd.sys (Boot Driver/Lavasoft AB)
Device \Driver\Tcpip \Device\RawIp Code 8A43E468
Device \Driver\Tcpip \Device\RawIp Code 8A545CC0
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
Device \Driver\SYMTDI \Device\SymTDI Code 8A4BCDF8
Device \Driver\Tcpip \Device\IPMULTICAST Code 8A43E468
Device \Driver\Tcpip \Device\IPMULTICAST Code 8A545CC0
Device \Driver\Ftdisk \Device\FtControl DGBusMon.SYS (Digital Guardian Agent Bus Filter for 2K/XP/Verdasys, Inc.)
---- EOF - GMER 1.0.15 ----