Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Admin tools all unavailable, seemingly fake dropbox and a few other pr

Malware unknown virus

  • Please log in to reply

#16
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Application Version.

 

Also, have had a few error messages pop up, throughout this process, I snapped pics, they are as follows.

Error- Could not list children of "/":

Response from the server was. "The last operation had a general error."  (box to select ok, or drop down with More Information)

 

More Information (Says)

 

Possible Solutions

This error comes directly from the online storage service. If the content of the error doesn't provide some clue about how to fix the

problem, these generic ideas might help.

 

-Shorten any long text strings you may have entered.

-Remove any less common characters.

-Try the request again a bit later.

 

______________________________

 

Microsoft Visual C++ Runtime Library

 

Runtime Error!

Program: C:\...

 

This application has requested the Runtime to terminate in an unusual way.

Please contact the application's support team for more information.

 

(This has been an ongoing one, exactly like this is written, then I got the following one on 7/10/17)

______________________________

 

Microsoft Visual C++ Runtime Library

 

Runtime Error!

Program: C:\WINDOWS\SysWOW64\DllHost.exe

 

R6034

An application has made an attempt to load the C runtime library

incorrectly.

Please contact the application's support team for more information.

 

In searching this error #, I found a post, interestingly enough, that describes my issue, with my main Microsoft acct basically being taken over, and using One Note, creating "guest" profiles on my machine, and basically taking over. Throughout the various people posting, they suggested several things causing it, in a Microsoft feed I think, anyway one suggestion was to run the Microsoft scanner, not the malicious tool, so as I'd mentioned, I had run that, and it removed a virus. Can you by chance tell me where to locate that log, as it may have additional info too?

 

________________________________

 

I also found this post, after eset notified me several times, about allowed Modified startup settings.

 

https://www.bleeping...9/scan-results/

 

I'm going to post this now, but have some log files to send you directly if possible.

 

Vino's Event Viewer v01c run on Windows 7 in English
Report run at 12/07/2017 2:28:03 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/07/2017 9:15:39 AM
Type: Error Category: 100
Event: 1000 Source: Application Error
Faulting application name: AdobeARM.exe, version: 1.824.21.1354, time stamp: 0x5858d0a7 Faulting module name: AdobeARM.exe, version: 1.824.21.1354, time stamp: 0x5858d0a7 Exception code: 0x40000015 Fault offset: 0x0005a780 Faulting process id: 0x22f8 Faulting application start time: 0x01d2faef6b3e6690 Faulting application path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Faulting module path: C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe Report Id: 07f29c6b-5aa2-4d69-ae60-2baebe24aacc Faulting package full name:  Faulting package-relative application ID:

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

Log: 'Application' Date/Time: 12/07/2017 3:52:33 AM
Type: Error Category: 3
Event: 3104 Source: Microsoft-Windows-Search
Enumerating user sessions to generate filter pools failed.

Details:
 (HRESULT : 0x80040210) (0x80040210)

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 12/07/2017 4:28:18 AM
Type: Warning Category: 1
Event: 1015 Source: Microsoft-Windows-Search
Event ID 3104 for the Windows Search Service has been suppressed 45 time(s) since 8:52:33 PM. This event is used to suppress Windows Search Service events that have occurred frequently within a short period of time.  See Event ID 3104 for further details on this event.

Log: 'Application' Date/Time: 11/07/2017 9:27:48 PM
Type: Warning Category: 7
Event: 508 Source: ESENT
SettingSyncHost (1184) {8C4962ED-5392-4F0C-B16F-68B87A6D22F8}: A request to write to the file "C:\Users\AIRWORX 2\AppData\Local\Microsoft\Windows\SettingSync\metastore\edb.log" at offset 110592 (0x000000000001b000) for 4096 (0x00001000) bytes succeeded, but took an abnormally long time (19 seconds) to be serviced by the OS. This problem is likely due to faulty hardware. Please contact your hardware vendor for further assistance diagnosing the problem.

Log: 'Application' Date/Time: 11/07/2017 7:13:41 PM
Type: Warning Category: 0
Event: 2901 Source: HP Active Health
Error getting Windows updates: System.Threading.ThreadAbortException: Thread was being aborted.    at Interop.WUApiLib.IUpdateSearcher.Search(String criteria)    at HP.ActiveHealth.Agents.WindowsUpdates.WindowsUpdatesAgent.GetWindowsUpdates()

Log: 'Application' Date/Time: 11/07/2017 7:13:18 PM
Type: Warning Category: 0
Event: 2903 Source: HP Active Health
Unable to get WindowsUpdate information in able time

Log: 'Application' Date/Time: 11/07/2017 7:13:15 PM
Type: Warning Category: 0
Event: 3 Source: HP Active Health
Error running a Casl EXECUTE Diags.ThermalDiagnostics command: Exception has been thrown by the target of an invocation.

Log: 'Application' Date/Time: 11/07/2017 7:13:15 PM
Type: Warning Category: 0
Event: 3 Source: HP Active Health
Error running a Casl EXECUTE Diags.ThermalDiagnostics command: Exception has been thrown by the target of an invocation.

Log: 'Application' Date/Time: 11/07/2017 7:13:15 PM
Type: Warning Category: 0
Event: 3 Source: HP Active Health
Error running a Casl EXECUTE Diags.ThermalDiagnostics command: Exception has been thrown by the target of an invocation.

Log: 'Application' Date/Time: 11/07/2017 7:13:15 PM
Type: Warning Category: 0
Event: 3 Source: HP Active Health
Error running a Casl EXECUTE Diags.ThermalDiagnostics command: Exception has been thrown by the target of an invocation.

Log: 'Application' Date/Time: 11/07/2017 7:13:09 PM
Type: Warning Category: 0
Event: 3 Source: HP Active Health
Error running a Casl GET EmbeddedController.AuditLog.JSON command: Exception has been thrown by the target of an invocation.

Log: 'Application' Date/Time: 11/07/2017 7:12:06 PM
Type: Warning Category: 0
Event: 2003 Source: Microsoft-Windows-Perflib
The configuration information of the performance library "C:\Windows\System32\perfts.dll" for the "TermService" service does not match the trusted performance library information stored in the registry. The functions in this library will not be treated as trusted.

Log: 'Application' Date/Time: 11/07/2017 7:03:24 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

Log: 'Application' Date/Time: 11/07/2017 7:03:24 PM
Type: Warning Category: 0
Event: 6000 Source: Microsoft-Windows-Winlogon
The winlogon notification subscriber <GPClient> was unavailable to handle a notification event.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2017 9:03:36 AM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {8D8F4F83-3594-4F07-8369-FC3C3CAE4919}  and APPID  {F72671A9-012C-4725-9D2F-2A4D32D65169}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 12/07/2017 3:32:12 AM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Apple Mobile Device service failed to start due to the following error:  The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 12/07/2017 3:32:12 AM
Type: Error Category: 0
Event: 7009 Source: Service Control Manager
A timeout was reached (30000 milliseconds) while waiting for the Apple Mobile Device service to connect.

Log: 'System' Date/Time: 12/07/2017 3:22:53 AM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {D63B10C5-BB46-4990-A94F-E40B9D520160}  and APPID  {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 11/07/2017 9:03:50 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {D63B10C5-BB46-4990-A94F-E40B9D520160}  and APPID  {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 11/07/2017 9:03:23 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {D63B10C5-BB46-4990-A94F-E40B9D520160}  and APPID  {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 11/07/2017 9:02:28 PM
Type: Error Category: 0
Event: 10016 Source: Microsoft-Windows-DistributedCOM
The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID  {D63B10C5-BB46-4990-A94F-E40B9D520160}  and APPID  {9CA88EE3-ACB7-47C8-AFC4-AB702511C276}  to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.

Log: 'System' Date/Time: 11/07/2017 8:56:33 PM
Type: Error Category: 1
Event: 20 Source: Microsoft-Windows-WindowsUpdateClient
Installation Failure: Windows failed to install the following update with error 0x8024200D: Feature update to Windows 10, version 1703.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7001 Source: Service Control Manager
The Computer Browser service depends on the Workstation service which failed to start because of the following error:  The account specified for this service is different from the account specified for other services running in the same process.

Log: 'System' Date/Time: 11/07/2017 8:08:18 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Workstation service failed to start due to the following error:  The account specified for this service is different from the account specified for other services running in the same process.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 12/07/2017 3:32:06 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\_??_USBSTOR#Disk&Ven_Generic&Prod_Flash_Disk&Rev_8.07#LHAA1011260818028816&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}.

Log: 'System' Date/Time: 11/07/2017 8:08:28 PM
Type: Warning Category: 0
Event: 4 Source: Microsoft-Windows-FilterManager
File System Filter 'wcifs' (Version 10.0, ?2016?-?09?-?15T09:42:03.000000000Z) failed to attach to volume '\Device\HarddiskVolumeShadowCopy1'.  The filter returned a non-standard final status of 0xC000000D.  This filter and/or its supporting applications should handle this condition.  If this condition persists, contact the vendor.

Log: 'System' Date/Time: 11/07/2017 8:06:18 PM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\_??_USBSTOR#Disk&Ven_Generic&Prod_Flash_Disk&Rev_8.07#LHAA1011260818028816&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}.

Log: 'System' Date/Time: 11/07/2017 7:09:48 PM
Type: Warning Category: 0
Event: 4 Source: Microsoft-Windows-FilterManager
File System Filter 'wcifs' (Version 10.0, ?2016?-?09?-?15T09:42:03.000000000Z) failed to attach to volume '\Device\HarddiskVolumeShadowCopy1'.  The filter returned a non-standard final status of 0xC000000D.  This filter and/or its supporting applications should handle this condition.  If this condition persists, contact the vendor.


  • 0

Advertisements


#17
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

I'm glad to hear we are making progress.  I'm running late today.  Usually get up at 6 but skipped my nap yesterday so the dog had to wake me up at 8 to go out.  

 

We can fix this error easily:

 

Log: 'System' Date/Time: 12/07/2017 3:32:06 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WudfRd failed to load for the device SWD\WPDBUSENUM\_??_USBSTOR#Disk&Ven_Generic&Prod_Flash_Disk&Rev_8.07#LHAA1011260818028816&0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}.

 

 
Search for
 
services.msc
 
hit Enter
 
This should bring up the Services Window.  Scroll down to
 
Windows Driver Foundation - User-mode Driver Framework
 
Right click and select Properties.
Change Startup Type: from Manual to Automatic.  OK.
 
The rest of the errors are either from yesterday or found on all Win 10s except for the Apple Mobile Device Service.  That one you can just reinstall if it's something you need and it's not working.
 
Let's try to run some scans to see if there is something FRST can't see:
 
 
 
Download aswMBR.exe  to your desktop.
The link is a direct download so the page won't change.
 
Right click the aswMBR.exe and select Run As Administrator to run it
Wait until the AV Scan shows up at the bottom left.
Change AV Scan: from Quick Scan to  C:\
Click the "Scan" button to start scan
If it asks you to allow the Avast engine to download then say Yes.  It will take a while to finish.  
On completion of the scan (Note if the Fix button is enabled and tell me but do not push any buttons) click save log, save it to your desktop and post in your next reply
 
If it crashes then try it again but uncheck Trace Disk IO Calls before hitting Scan.
 
 
 
Then try MBAR:
 
 
I don't have canned instructions for it yet but it should be fairly straight forward.  Hit the Download button, Save it then right click and Run As Admin.  It will go faster if you can pause your anti-virus.
 
Finally try Rogue Killer:
 
 
 
Portable 64 bits <==USE THIS ONE
 
Download and Save.
 
 
 
Right click on the downloaded file (RogueKillerX64.exe or RogueKiller.exe)  and Run As admin
 
Start Scan
Start Scan
 
Will take about 20 minutes to complete.
 
Open Report
Export TXT (save it to your desktop as rk) Save
 
Do not let Rogue Killer remove anything until you hear from me.  Leave Rogue Killer up (but minimized) so you won't have to rescan.
 
Open rk.txt and copy and paste it to your next Reply. 
 

  • 0

#18
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

I'm a bit unsure if the first one is running correctly or not, it runs, then stops, but the "stop" button is still enabled, seemingly like it hangs up. Anyway, I can retry it, with the item you suggested unchecked. Does it actively visibly I should ask, throughout the whole scan?

 

I will mention the fixMBR button is enabled, when I selected stop?

 

aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2017-07-12 06:14:17
-----------------------------
06:14:17.132    OS Version: Windows x64 6.2.9200
06:14:17.132    Number of processors: 4 586 0x1301
06:14:17.133    ComputerName: AIRWORX2-PC  UserName: AIRWORX 2
06:14:20.270    Initialize success
06:14:20.275    VM: initialized successfully
06:14:20.276    VM: Amd CPU supported
06:16:07.011    AVAST engine defs: 17030301
06:16:22.388    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000029
06:16:22.391    Disk 0 Vendor: ST2000DM001-1CH164 HP34 Size: 1907729MB BusType: 11
06:16:22.752    Disk 0 MBR read successfully
06:16:22.754    Disk 0 MBR scan
06:16:22.805    Disk 0 unknown MBR code
06:16:22.821    Disk 0 Partition 1 00     EE            GPT           2097151 MB offset 1
06:16:22.890    Disk 0 scanning C:\WINDOWS\system32\drivers
06:16:41.482    Service scanning
06:17:03.918    Modules scanning
06:17:03.925    Disk 0 trace - called modules:
06:17:03.955    ntoskrnl.exe CLASSPNP.SYS disk.sys vsflt53.sys storport.sys hal.dll storahci.sys
06:17:03.961    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffdf846ad6a060]
06:17:03.966    3 CLASSPNP.SYS[fffff800e1155efb] -> nt!IofCallDriver -> [0xffffdf8469452380]
06:17:03.971    5 vsflt53.sys[fffff800e0331cfd] -> nt!IofCallDriver -> \Device\00000029[0xffffdf846ab42060]
06:17:16.835    AVAST engine scan C:\
06:43:15.215    Disk 0 MBR has been saved successfully to "C:\Users\AIRWORX 2\Desktop\MBR.dat"
06:43:15.224    The log file has been saved successfully to "C:\Users\AIRWORX 2\Desktop\aswMBR.txt"

 

I'll start on the next one, for now.
 


  • 0

#19
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

The Avast scan of the C:\ drive takes a while so it was probably working OK.  It doesn't show you anything until it finishes.  The rootkit scan is the most important and it finishes early so that's good enough.

 

Go on to MBAR


  • 0

#20
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

The malware bites found one malware object.

C:\Windows\Temp\services.exe.mui (Trojan.Agent)

 

The option is cleanup or  exit?


  • 0

#21
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

The malware bites found one malware object.

C:\Windows\Temp\services.exe.mui Trojan.Agent there are no - but seemingly not allowing me to post as is

 

The option is cleanup or  exit?


  • 0

#22
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

cleanup


  • 0

#23
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

doing that now, how can I delete the duplicate posts, it wasn't accepting it, and I apparently got impatient. Sorry


  • 0

#24
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

That's common on this forum.  Don't know why but sometimes it takes a while to post.  I have hidden your extra posts.


  • 0

#25
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

 

Latest scan

RogueKiller V12.11.6.0 (x64) [Jul 10 2017] (Premium) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.co...ad/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : AIRWORX 2 [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 07/12/2017 08:20:33 (Duration : 00:54:18)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 2 ¤¤¤
[PUM.HomePage] (X64) HKEY_USERS\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://login.secure...mail.airworx.us  -> Found
[PUM.HomePage] (X86) HKEY_USERS\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main | Start Page : https://login.secure...mail.airworx.us  -> Found

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0: ST2000DM001-1CH164 +++++
--- User ---
[MBR] f86f4a6d732d5d11731309772e1fbe7f
[BSP] 2bf3dd60e501e1f0f760c942b8d1b006 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1023 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2097152 | Size: 360 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2834432 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 3096576 | Size: 1886686 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 3867029504 | Size: 450 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 3867951104 | Size: 19076 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1: Generic Flash Disk USB Device +++++
--- User ---
[MBR] 1c42ac96cea7b70222a78c22ed7f378f
[BSP] 6f61b52460ecc86ec118b4d775eee70e : Unknown|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x6e) [VISIBLE] Offset (sectors): 1948285285 | Size: 831044 MB
3 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 28049408 | Size: 0 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )

 

And a window popped up letting me know how to remove PUM that says

 

What is a PUM?

A PUM (for Potentially Unwanted Modification) is a sensitive modification made by a program which can be malware or legit, or even made by the user. Such detection is triggered depending on what is modified.

Several examples:

PUM.Proxy: A proxy is a program running either locally (on your machine) or on a remote machine (server) that acts as a web filter. It’s able to read, decode and filter all your internet traffic and bounce some requests based on rules. In an enterprise context, proxies are used to protect endpoints or deny some websites at work (Facebook, …). At home, most of the time these proxies are malicious.

Malware use proxies to deny access to help forums, or download websites (they don’t want you to be able to disinfect your machine). They are also used to retrieve information regarding your internet habits, and inject ads or redirect to malicious websites. What you need to know basically is that a proxy can read and modify all internet traffic that passes through it.

The following example is made with a LEGIT program, fiddler. It demonstrates what a proxy can do (running locally).


  • 0

Advertisements


#26
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

Looks harmless so just close Rogue Killer


  • 0

#27
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

Try Kaspersky's online scan:

 

https://usa.kaspersk...free-virus-scan

 

Click on the red Download Now  button and follow the instructions.


  • 0

#28
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

This is the first one from earlier

 

aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2017-07-12 06:14:17
-----------------------------
06:14:17.132    OS Version: Windows x64 6.2.9200
06:14:17.132    Number of processors: 4 586 0x1301
06:14:17.133    ComputerName: AIRWORX2-PC  UserName: AIRWORX 2
06:14:20.270    Initialize success
06:14:20.275    VM: initialized successfully
06:14:20.276    VM: Amd CPU supported
06:16:07.011    AVAST engine defs: 17030301
06:16:22.388    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000029
06:16:22.391    Disk 0 Vendor: ST2000DM001-1CH164 HP34 Size: 1907729MB BusType: 11
06:16:22.752    Disk 0 MBR read successfully
06:16:22.754    Disk 0 MBR scan
06:16:22.805    Disk 0 unknown MBR code
06:16:22.821    Disk 0 Partition 1 00     EE            GPT           2097151 MB offset 1
06:16:22.890    Disk 0 scanning C:\WINDOWS\system32\drivers
06:16:41.482    Service scanning
06:17:03.918    Modules scanning
06:17:03.925    Disk 0 trace - called modules:
06:17:03.955    ntoskrnl.exe CLASSPNP.SYS disk.sys vsflt53.sys storport.sys hal.dll storahci.sys
06:17:03.961    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffdf846ad6a060]
06:17:03.966    3 CLASSPNP.SYS[fffff800e1155efb] -> nt!IofCallDriver -> [0xffffdf8469452380]
06:17:03.971    5 vsflt53.sys[fffff800e0331cfd] -> nt!IofCallDriver -> \Device\00000029[0xffffdf846ab42060]
06:17:16.835    AVAST engine scan C:\
06:43:15.215    Disk 0 MBR has been saved successfully to "C:\Users\AIRWORX 2\Desktop\MBR.dat"
06:43:15.224    The log file has been saved successfully to "C:\Users\AIRWORX 2\Desktop\aswMBR.txt"

aswMBR version 1.0.1.2290 Copyright© 2014 AVAST Software
Run date: 2017-07-12 11:18:06
-----------------------------
11:18:06.595    OS Version: Windows x64 6.2.9200
11:18:06.596    Number of processors: 4 586 0x1301
11:18:06.597    ComputerName: AIRWORX2-PC  UserName: AIRWORX 2
11:18:14.790    Initialize success
11:18:14.825    VM: initialized successfully
11:18:14.897    VM: Amd CPU supported
11:20:10.645    AVAST engine defs: 17030301
11:20:24.943    Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000029
11:20:24.945    Disk 0 Vendor: ST2000DM001-1CH164 HP34 Size: 1907729MB BusType: 11
11:20:25.114    Disk 0 MBR read successfully
11:20:25.119    Disk 0 MBR scan
11:20:25.141    Disk 0 unknown MBR code
11:20:25.147    Disk 0 Partition 1 00     EE            GPT           2097151 MB offset 1
11:20:25.204    Disk 0 scanning C:\WINDOWS\system32\drivers
11:20:37.662    Service scanning
11:20:55.393    Modules scanning
11:20:55.407    Disk 0 trace - called modules:
11:20:55.487    ntoskrnl.exe CLASSPNP.SYS disk.sys vsflt53.sys storport.sys hal.dll storahci.sys
11:20:55.498    1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xffffb3866e764060]
11:20:55.506    3 CLASSPNP.SYS[fffff80b60005efb] -> nt!IofCallDriver -> [0xffffb3866e690970]
11:20:55.514    5 vsflt53.sys[fffff80b5e931cfd] -> nt!IofCallDriver -> \Device\00000029[0xffffb3866dd47060]
11:20:57.003    AVAST engine scan C:\
16:00:35.947    Disk 0 statistics 16672176/0/0 @ 0.61 MB/s
16:00:35.955    Scan finished successfully
16:08:33.065    Disk 0 MBR has been saved successfully to "C:\Users\AIRWORX 2\Desktop\MBR.dat"
16:08:33.083    The log file has been saved successfully to "C:\Users\AIRWORX 2\Desktop\aswMBR.txt"

 


  • 0

#29
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

aswmbr is from Avast.  This is Kaspersky


  • 0

#30
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

This is a redo of the Rogue Killer this am??? Not sure if it's b/c I disabled firewall and anti for the scan this am, as well as all day after I had run this one?

 

 

RogueKiller V12.11.6.0 (x64) [Jul 10 2017] (Premium) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.co...ad/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : AIRWORX 2 [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 07/13/2017 05:20:32 (Duration : 01:09:23)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 2159 (Driver: Loaded) ¤¤¤
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE[0] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE_NAMED_PIPE[1] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CLOSE[2] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_READ[3] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_WRITE[4] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_INFORMATION[5] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_INFORMATION[6] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_EA[7] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_EA[8] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_FLUSH_BUFFERS[9] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_VOLUME_INFORMATION[10] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_VOLUME_INFORMATION[11] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DIRECTORY_CONTROL[12] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_FILE_SYSTEM_CONTROL[13] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DEVICE_CONTROL[14] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SHUTDOWN[16] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_LOCK_CONTROL[17] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CLEANUP[18] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE_MAILSLOT[19] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_SECURITY[20] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_SECURITY[21] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_POWER[22] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SYSTEM_CONTROL[23] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DEVICE_CHANGE[24] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_QUOTA[25] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_QUOTA[26] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_PNP[27] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - DriverUnload[29] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b6004d210
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_CREATE_NAMED_PIPE[1] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_WRITE[4] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_INFORMATION[5] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_INFORMATION[6] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_EA[7] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_EA[8] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_VOLUME_INFORMATION[10] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_VOLUME_INFORMATION[11] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_DIRECTORY_CONTROL[12] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_FILE_SYSTEM_CONTROL[13] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SHUTDOWN[16] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_LOCK_CONTROL[17] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_CREATE_MAILSLOT[19] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_SECURITY[20] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_SECURITY[21] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_DEVICE_CHANGE[24] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_QUOTA[25] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_QUOTA[26] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!ParseApplicationUserModelId : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5f870
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!FindPackagesByPackageFamily : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5f3d0
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!GetPackagesByPackageFamily : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5d860
[IAT:Addr] (explorer.exe) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ shell32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shell32.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5180
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c4230
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c1900
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfeb0
[IAT:Addr] (explorer.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ imm32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ msctf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ ole32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ comctl32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ SndVolSSO.DLL) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ oleacc.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ explorerframe.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ explorerframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ twinui.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Windows.UI.Immersive.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Windows.UI.Immersive.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!CloseState : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5dda0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!OpenStateExplicit : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5dde0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!GetSystemAppDataKey : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5e210
[IAT:Addr] (explorer.exe @ ntshrui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (explorer.exe @ aticfx64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (explorer.exe @ atiuxp64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr(Microsoft)] (explorer.exe @ atidxx64.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b88900
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d37b0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dd490
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (explorer.exe @ atidxx64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr(Microsoft)] (explorer.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61c50
[IAT:Addr(Microsoft)] (explorer.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mscoreei.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!GetCurrentProcessorNumber : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615cc0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!FlushProcessWriteBuffers : C:\Windows\System32\ntdll.dll @ 0x7ffaeb617c80
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!AddVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6300
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!RemoveVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f59d0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ clrjit.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ clrjit.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7bea9d0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beae50
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (explorer.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ ieframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ stobject.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ InputSwitch.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ prnfldr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ DeviceSetupManagerAPI.dll) kernel32!PackageFamilyNameFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61bd0
[IAT:Addr] (explorer.exe @ DXP.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shdocvw.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Actioncenter.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ PortableDeviceApi.dll) kernel32!GetCurrentPackageFamilyName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5bef0
[IAT:Addr] (explorer.exe @ SettingMonitor.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ pnidui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ srchadmin.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ bthprops.cpl) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ SyncCenter.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (explorer.exe @ SyncCenter.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ davhlpr.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ hgcpl.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ duser.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ FXSST.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ FXSST.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ FXSST.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ FXSST.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ winspool.drv) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (explorer.exe @ winspool.drv) kernel32!GetCurrentPackageFamilyName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5bef0
[IAT:Addr] (explorer.exe @ GdiPlus.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ IconCodecService.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wscapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wscui.cpl) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ tishell64.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ tishell64.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ syncui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ syncui.dll) user32!DefDlgProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615e90
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ LoggingPlatform64.DLL) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ LoggingPlatform64.DLL) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ dui70.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ tiptsf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ UIRibbon.dll) gdi32!ScriptBreak : C:\Windows\System32\gdi32full.dll @ 0x7ffae7f8d9e0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) gdi32!ScriptItemize : C:\Windows\System32\gdi32full.dll @ 0x7ffae7f9e8b0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b74d20
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b8e2e0
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ UIRibbon.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ daxexec.dll) kernel32!FormatApplicationUserModelId : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b642b0
[IAT:Addr(Microsoft)] (explorer.exe @ daxexec.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (explorer.exe @ NPSMDesktopProvider.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ zipfldr.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (explorer.exe @ wpdshext.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b8e2e0
[IAT:Addr(Microsoft)] (explorer.exe @ wpdshext.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b74d20
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SetThreadpoolTimerEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfda0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf800
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventActivityIdControl : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e1290
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpdshext.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61c50
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5180
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c4230
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c1900
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfeb0
[IAT:Addr] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7bea9d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beae50
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97820
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97360
[IAT:Addr] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97820
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d972a0
[IAT:Addr] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b89de0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b94040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beb8f0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d972a0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb585b20
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ explorerframe.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ explorerframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ explorerframe.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ msfeeds.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ msfeeds.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97520
[IAT:Addr(Microsoft)] (iexplore.exe @ ntshrui.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ ntshrui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ntshrui.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ ntlanman.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ davhlpr.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr(Microsoft)] (iexplore.exe @ dui70.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ dui70.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ duser.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ tiptsf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoree.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoree.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoreei.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mscoreei.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!GetCurrentProcessorNumber : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615cc0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (iexplore.exe @ clr.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!FlushProcessWriteBuffers : C:\Windows\System32\ntdll.dll @ 0x7ffaeb617c80
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!AddVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6300
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!RemoveVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f59d0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr(Microsoft)] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (iexplore.exe @ clrjit.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ clrjit.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ clrjit.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (iexplore.exe @ zipfldr.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ zipfldr.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ zipfldr.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetTickCount : C:\Windows\System32\KERNELBASE.dll @ 0x76031940 (call dword [0x75a015dc])
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetNativeSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034cf0 (jmp dword [0x75a015f8])
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetSystemTimeAsFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7601c450 (jmp dword [0x75a0160c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateSemaphoreExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b070 (jmp dword [0x75a01520])
[IAT:Inl] (iexplore.exe) kernel32!SetLastError : C:\Windows\System32\ntdll.dll @ 0x777792b0 (jmp dword [0x75a019e0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetCommandLineW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e140 (jmp dword [0x75a011f8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseSemaphore : C:\Windows\System32\KERNELBASE.dll @ 0x760557c0 (jmp dword [0x75a01568])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringA : C:\Windows\System32\KERNELBASE.dll @ 0x760575e0 (jmp dword [0x75a00c90])
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObject : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae60 (jmp dword [0x75a01580])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseMutex : C:\Windows\System32\KERNELBASE.dll @ 0x76031b00 (jmp dword [0x75a01564])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetLastError : C:\Windows\System32\KERNELBASE.dll @ 0x76029f30 (jmp dword [0x75a00cd0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringW : C:\Windows\System32\KERNELBASE.dll @ 0x760574f0 (jmp dword [0x75a00c94])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObjectEx : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae80 (jmp dword [0x75a01584])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OpenSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b330 (jmp dword [0x75a01560])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CloseHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7602ad80 (jmp dword [0x75a00eac])
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateMutexExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b960 (jmp dword [0x75a01528])
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetProcessHeap : C:\Windows\System32\KERNELBASE.dll @ 0x76031c20 (jmp dword [0x75a00ec8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!IsDebuggerPresent : C:\Windows\System32\KERNELBASE.dll @ 0x7603dda0 (jmp dword [0x75a00c8c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!Sleep : C:\Windows\System32\KERNELBASE.dll @ 0x76032d70 (jmp dword [0x75a00a6c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetStartupInfoW : C:\Windows\System32\KERNELBASE.dll @ 0x7603a600 (jmp dword [0x75a012d8])
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x76017e20
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x760583d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SleepEx : C:\Windows\System32\KERNELBASE.dll @ 0x76032d90 (jmp dword [0x75a01578])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b560 (jmp dword [0x75a01534])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetThreadUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76048d70 (jmp dword [0x75a00fd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!WriteFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029360 (jmp dword [0x75a00e48])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFilePointer : C:\Windows\System32\KERNELBASE.dll @ 0x76033440 (jmp dword [0x75a00e30])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a5c0 (jmp dword [0x75a00dac])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesExW : C:\Windows\System32\KERNELBASE.dll @ 0x76039140 (jmp dword [0x75a00d88])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DeleteFileW : C:\Windows\System32\KERNELBASE.dll @ 0x76055330 (jmp dword [0x75a00d18])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSizeEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603c060 (jmp dword [0x75a00d98])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CompareFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x760390b0 (jmp dword [0x75a00dc0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetVolumePathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76050e20 (jmp dword [0x75a00df4])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!AreFileApisANSI : C:\Windows\System32\KERNELBASE.dll @ 0x7604c350 (jmp dword [0x75a009c4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFullPathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76039070 (jmp dword [0x75a00dd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c7a0 (jmp dword [0x75a00d8c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b4a0 (jmp dword [0x75a01524])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76033d80 (jmp dword [0x75a01570])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!ResetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76035530 (jmp dword [0x75a0156c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x76049b40 (jmp dword [0x75a00d9c])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DuplicateHandle : C:\Windows\System32\KERNELBASE.dll @ 0x760361d0 (jmp dword [0x75a00eb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x777b4020
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778ac30
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778acf0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!RaiseException : C:\Windows\System32\KERNELBASE.dll @ 0x7603a990 (jmp dword [0x75a00cbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7604b4e0 (jmp dword [0x75a00e2c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindClose : C:\Windows\System32\KERNELBASE.dll @ 0x760350a0 (jmp dword [0x75a00d24])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindNextFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a1f0 (jmp dword [0x75a00d58])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindFirstFileExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c090 (jmp dword [0x75a00dc4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSize : C:\Windows\System32\KERNELBASE.dll @ 0x76034c80 (jmp dword [0x75a00d94])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!ReadFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029d40 (jmp dword [0x75a00e0c])
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetCommandLineA : C:\Windows\System32\KERNELBASE.dll @ 0x7603e210 (jmp dword [0x75a011fc])
[IAT:Inl] (iexplore.exe @ eplgIE.dll) kernel32!RtlUnwind : C:\Windows\System32\ntdll.dll @ 0x777af000 (jmp dword [0x75a014b8])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetACP : C:\Windows\System32\KERNELBASE.dll @ 0x76039cc0 (jmp dword [0x75a01050])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetOEMCP : C:\Windows\System32\KERNELBASE.dll @ 0x76058bc0 (jmp dword [0x75a01074])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!TlsAlloc : C:\Windows\System32\KERNELBASE.dll @ 0x760397e0 (jmp dword [0x75a01278])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetFileType : C:\Windows\System32\KERNELBASE.dll @ 0x76036110 (jmp dword [0x75a00da0])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetEnvironmentStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76033560 (jmp dword [0x75a01214])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleCP : C:\Windows\System32\KERNELBASE.dll @ 0x760936e0 (jmp dword [0x75a00bac])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleMode : C:\Windows\System32\KERNELBASE.dll @ 0x7601fcf0 (jmp dword [0x75a00ba4])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!WriteConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094410 (jmp dword [0x75a00b78])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FlushFileBuffers : C:\Windows\System32\KERNELBASE.dll @ 0x76057fb0 (jmp dword [0x75a00d64])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetObjectW : C:\Windows\System32\gdi32full.dll @ 0x75ae2540 (jmp dword [0x74947018])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b05e80 (jmp dword [0x74947050])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetBitmapBitsSize : C:\Windows\System32\gdi32full.dll @ 0x75ae29c0 (jmp dword [0x74947628])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75ae4ee0 (jmp dword [0x74947100])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiValidateHandle : C:\Windows\System32\gdi32full.dll @ 0x75ae2490 (jmp dword [0x749476c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetMapMode : C:\Windows\System32\gdi32full.dll @ 0x75b072a0 (jmp dword [0x749470fc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetHFONT : C:\Windows\System32\gdi32full.dll @ 0x75b12980 (jmp dword [0x74947758])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b05f30 (jmp dword [0x749470a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDCOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b13c00 (jmp dword [0x7494702c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiFixUpHandle : C:\Windows\System32\gdi32full.dll @ 0x75b0cac0 (jmp dword [0x7494761c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiPrinterThunk : C:\Windows\System32\gdi32full.dll @ 0x75b4c7c0 (jmp dword [0x74947690])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiLoadType1Fonts : C:\Windows\System32\gdi32full.dll @ 0x75b3bb90 (jmp dword [0x74947674])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiAddFontResourceW : C:\Windows\System32\gdi32full.dll @ 0x75b3ba60 (jmp dword [0x7494757c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiProcessSetup : C:\Windows\System32\gdi32full.dll @ 0x75ae4090 (jmp dword [0x74947694])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiDllInitialize : C:\Windows\System32\gdi32full.dll @ 0x75ae3ea0 (jmp dword [0x749442d8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnableEUDC : C:\Windows\System32\gdi32full.dll @ 0x75b1c570 (jmp dword [0x74947444])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertBitmapV5 : C:\Windows\System32\gdi32full.dll @ 0x75b3e180 (jmp dword [0x7494759c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertToDevmodeW : C:\Windows\System32\gdi32full.dll @ 0x75b39e20 (jmp dword [0x749475bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!MirrorRgn : C:\Windows\System32\gdi32full.dll @ 0x75b3a3b0 (jmp dword [0x749477e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b174c0 (jmp dword [0x749476dc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b06e80 (jmp dword [0x749470a4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!ExcludeClipRect : C:\Windows\System32\gdi32full.dll @ 0x75b1abd0 (jmp dword [0x74947008])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CreateEllipticRgn : C:\Windows\System32\gdi32full.dll @ 0x75b39c40 (jmp dword [0x749472f4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!PolyPatBlt : C:\Windows\System32\gdi32full.dll @ 0x75b10850 (jmp dword [0x74947be4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetTextCharacterExtra : C:\Windows\System32\gdi32full.dll @ 0x75b07a40 (jmp dword [0x749471bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayoutWidth : C:\Windows\System32\gdi32full.dll @ 0x75b18d20 (jmp dword [0x74947c70])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertAndCheckDC : C:\Windows\System32\gdi32full.dll @ 0x75b16730 (jmp dword [0x74947594])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b16910 (jmp dword [0x74947c4c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyEnhMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b4dd60 (jmp dword [0x749472c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b44a70 (jmp dword [0x749472d0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharsetInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1b1d0 (jmp dword [0x749477ac])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!QueryFontAssocStatus : C:\Windows\System32\gdi32full.dll @ 0x75b196e0 (jmp dword [0x74947bfc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharWidthInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1ca20 (jmp dword [0x74947704])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceW : C:\Windows\System32\gdi32full.dll @ 0x75ae8930 (jmp dword [0x74947174])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsW : C:\Windows\System32\gdi32full.dll @ 0x75b15a30 (jmp dword [0x74947134])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsA : C:\Windows\System32\gdi32full.dll @ 0x75b36d40 (jmp dword [0x749476e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b076a0 (jmp dword [0x749470e0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceAliasW : C:\Windows\System32\gdi32full.dll @ 0x75ae8030 (jmp dword [0x749477b8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnumFontsW : C:\Windows\System32\gdi32full.dll @ 0x75b10e80 (jmp dword [0x749471a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b51010 (jmp dword [0x749475c0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b51030 (jmp dword [0x749475c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b50f20 (jmp dword [0x749475a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b50f90 (jmp dword [0x749475b0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75afd6e0 (jmp dword [0x74947178])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!TextOutW : C:\Windows\System32\gdi32full.dll @ 0x75b47680 (jmp dword [0x74947184])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetWindowExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecf90 (jmp dword [0x749470f0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetViewportExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecec0 (jmp dword [0x749477c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBkMode : C:\Windows\System32\gdi32full.dll @ 0x75b043f0 (jmp dword [0x7494706c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCharDimensions : C:\Windows\System32\gdi32full.dll @ 0x75b13cb0 (jmp dword [0x7494762c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharset : C:\Windows\System32\gdi32full.dll @ 0x75b17c90 (jmp dword [0x749471a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCodePage : C:\Windows\System32\gdi32full.dll @ 0x75b11760 (jmp dword [0x74947630])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextExtentPointW : C:\Windows\System32\gdi32full.dll @ 0x75afaf60 (jmp dword [0x74947194])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!OffsetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b14060 (jmp dword [0x749470e8])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!InvalidateRect : C:\Windows\System32\win32u.dll @ 0x753124c0 (jmp dword [0x74bffb9c])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetKeyboardLayoutList : C:\Windows\System32\win32u.dll @ 0x75312a00 (jmp dword [0x74bffc8c])
[IAT:Addr(Microsoft)] (iexplore.exe @ gdi32full.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetDC : C:\Windows\System32\win32u.dll @ 0x75312520 (jmp dword [0x74bffcc4])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetForegroundWindow : C:\Windows\System32\win32u.dll @ 0x75312840 (jmp dword [0x74bffcac])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75312bf0 (jmp dword [0x74bffc88])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!DestroyWindow : C:\Windows\System32\win32u.dll @ 0x75312e40 (jmp dword [0x74bffd50])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!ShowWindow : C:\Windows\System32\win32u.dll @ 0x753129f0 (jmp dword [0x74bffa18])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!EndPaint : C:\Windows\System32\win32u.dll @ 0x75312610 (jmp dword [0x74bffd00])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!BeginPaint : C:\Windows\System32\win32u.dll @ 0x753125f0 (jmp dword [0x74bffdb8])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetWindowPos : C:\Windows\System32\win32u.dll @ 0x753126c0 (jmp dword [0x74bffa2c])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetCapture : C:\Windows\System32\win32u.dll @ 0x75312910 (jmp dword [0x74bffab8])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetFocus : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcessMitigationPolicy : C:\Windows\System32\KERNELBASE.dll @ 0x7603af60
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetThreadLocale : C:\Windows\System32\KERNELBASE.dll @ 0x7603b480 (jmp dword [0x75a01060])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetSystemDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c630 (jmp dword [0x75a01064])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl] (iexplore.exe @ imm32.dll) kernel32!RtlCaptureContext : C:\Windows\System32\ntdll.dll @ 0x777d2e00 (jmp dword [0x75a014c4])
[IAT:Inl] (iexplore.exe @ imm32.dll) gdi32!GetTextExtentPoint32W : C:\Windows\System32\gdi32full.dll @ 0x75afe460 (jmp dword [0x74947198])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CopyFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7603f280 (jmp dword [0x75a00ea4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempPathW : C:\Windows\System32\KERNELBASE.dll @ 0x7603d040 (jmp dword [0x75a00de4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempFileNameW : C:\Windows\System32\KERNELBASE.dll @ 0x7604f170 (jmp dword [0x75a00ddc])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bb760
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bba70
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b3d0 (jmp dword [0x75a0155c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034d50 (jmp dword [0x75a01600])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c490 (jmp dword [0x75a01030])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x76035480 (jmp dword [0x75a01604])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionAndSpinCount : C:\Windows\System32\KERNELBASE.dll @ 0x76034c60 (jmp dword [0x75a0154c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604fe20 (jmp dword [0x75a00e38])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetFinalPathNameByHandleW : C:\Windows\System32\KERNELBASE.dll @ 0x76046b60 (jmp dword [0x75a00dc8])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLocalTime : C:\Windows\System32\KERNELBASE.dll @ 0x760344b0 (jmp dword [0x75a015f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x760345d0 (jmp dword [0x75a01668])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToLocalFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604a210 (jmp dword [0x75a00d20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc440 (jmp dword [0x75a016cc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateMutexA : C:\Windows\System32\KERNELBASE.dll @ 0x76051fb0 (jmp dword [0x75a01530])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjects : C:\Windows\System32\KERNELBASE.dll @ 0x76031c30 (jmp dword [0x75a015b8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x76057af0 (jmp dword [0x75a00e28])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b670 (jmp dword [0x75a01544])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b040 (jmp dword [0x75a015b4])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034ec0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CancelWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045b70 (jmp dword [0x75a01540])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76050660 (jmp dword [0x75a01034])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76047db0 (jmp dword [0x75a01068])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjectsEx : C:\Windows\System32\KERNELBASE.dll @ 0x76031c60 (jmp dword [0x75a0157c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045120 (jmp dword [0x75a01574])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c070 (jmp dword [0x75a00d44])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDriveTypeW : C:\Windows\System32\KERNELBASE.dll @ 0x76035950 (jmp dword [0x75a00d7c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventA : C:\Windows\System32\KERNELBASE.dll @ 0x7602b5d0 (jmp dword [0x75a0153c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateFile2 : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6a0 (jmp dword [0x75a00db4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76057ee0 (jmp dword [0x75a016d8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LocalFileTimeToFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604edf0 (jmp dword [0x75a00dfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetEndOfFile : C:\Windows\System32\KERNELBASE.dll @ 0x7603d520 (jmp dword [0x75a00e20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDiskFreeSpaceExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603bbe0 (jmp dword [0x75a00d70])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!UnlockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6d0 (jmp dword [0x75a00e40])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604cb60 (jmp dword [0x75a00e00])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLogicalDriveStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76059010 (jmp dword [0x75a00dd4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!QueryDosDeviceW : C:\Windows\System32\KERNELBASE.dll @ 0x76056b40 (jmp dword [0x75a00e08])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetVersion : C:\Windows\System32\KERNELBASE.dll @ 0x76057ca0 (jmp dword [0x75a01610])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x7603e150 (jmp dword [0x75a00a3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034fa0 (jmp dword [0x75a01550])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!ReleaseActCtx : C:\Windows\System32\KERNELBASE.dll @ 0x76057c50 (jmp dword [0x75a014f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76034390 (jmp dword [0x75a00a40])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b720 (jmp dword [0x75a01558])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!RemoveDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e600 (jmp dword [0x75a00e1c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76039bb0 (jmp dword [0x75a00db8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b43e80 (jmp dword [0x7494704c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiTransparentBlt : C:\Windows\System32\gdi32full.dll @ 0x75b182f0 (jmp dword [0x74947108])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiGradientFill : C:\Windows\System32\gdi32full.dll @ 0x75b134a0 (jmp dword [0x7494710c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiAlphaBlend : C:\Windows\System32\gdi32full.dll @ 0x75b107c0 (jmp dword [0x749470cc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b0cb10 (jmp dword [0x74947104])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateHalftonePalette : C:\Windows\System32\gdi32full.dll @ 0x75b1b1b0 (jmp dword [0x74947304])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!PtInRegion : C:\Windows\System32\gdi32full.dll @ 0x75b3a610 (jmp dword [0x7494436c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateFontW : C:\Windows\System32\gdi32full.dll @ 0x75b16130 (jmp dword [0x749471b8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiFlush : C:\Windows\System32\gdi32full.dll @ 0x75b13800 (jmp dword [0x74947060])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCPenColor : C:\Windows\System32\gdi32full.dll @ 0x75b441a0 (jmp dword [0x74947c5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b44000 (jmp dword [0x7494701c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetTextExtentExPointW : C:\Windows\System32\gdi32full.dll @ 0x75b17ea0 (jmp dword [0x74947168])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateDIBPatternBrushPt : C:\Windows\System32\gdi32full.dll @ 0x75b39c00 (jmp dword [0x74947124])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!MoveWindow : C:\Windows\System32\win32u.dll @ 0x75312a50 (jmp dword [0x74bffb58])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WaitMessage : C:\Windows\System32\win32u.dll @ 0x75312540 (jmp dword [0x74bff9b4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackPopupMenuEx : C:\Windows\System32\win32u.dll @ 0x753169b0 (jmp dword [0x74bff9f4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DeleteMenu : C:\Windows\System32\win32u.dll @ 0x75313030 (jmp dword [0x74bffd5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!CopyAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75312740 (jmp dword [0x74bffd70])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!KillTimer : C:\Windows\System32\win32u.dll @ 0x75312630 (jmp dword [0x74bffb78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetDoubleClickTime : C:\Windows\System32\win32u.dll @ 0x75312fd0 (jmp dword [0x74bffcb0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WindowFromPoint : C:\Windows\System32\win32u.dll @ 0x753125c0 (jmp dword [0x74bff9ac])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageTime : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!AttachThreadInput : C:\Windows\System32\win32u.dll @ 0x75313320 (jmp dword [0x74bffdbc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetSystemMenu : C:\Windows\System32\win32u.dll @ 0x75312a80 (jmp dword [0x74bffc1c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!FlashWindowEx : C:\Windows\System32\win32u.dll @ 0x75315bd0 (jmp dword [0x74bffcf4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowDC : C:\Windows\System32\win32u.dll @ 0x75312ab0 (jmp dword [0x74bffbf8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackMouseEvent : C:\Windows\System32\win32u.dll @ 0x75313210 (jmp dword [0x74bff9f8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SendInput : C:\Windows\System32\win32u.dll @ 0x75312c90 (jmp dword [0x74bffad8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetGUIThreadInfo : C:\Windows\System32\win32u.dll @ 0x75313450 (jmp dword [0x74bffca8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x753131b0 (jmp dword [0x74bffbe8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetTitleBarInfo : C:\Windows\System32\win32u.dll @ 0x75312d60 (jmp dword [0x74bffc14])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75313350 (jmp dword [0x74bffa78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!PrintWindow : C:\Windows\System32\win32u.dll @ 0x753163a0 (jmp dword [0x74bffb38])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetComboBoxInfo : C:\Windows\System32\win32u.dll @ 0x75315c60 (jmp dword [0x74bffcd0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RedrawWindow : C:\Windows\System32\win32u.dll @ 0x753125b0 (jmp dword [0x74bffb24])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageExtraInfo : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ShowScrollBar : C:\Windows\System32\win32u.dll @ 0x75312850 (jmp dword [0x74bffa20])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x75313280 (jmp dword [0x74bffa30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75313260 (jmp dword [0x74bffac8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ChangeWindowMessageFilterEx : C:\Windows\System32\win32u.dll @ 0x753158f0 (jmp dword [0x74bffda0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EnumDisplayMonitors : C:\Windows\System32\win32u.dll @ 0x75312920 (jmp dword [0x74bffcfc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetClipCursor : C:\Windows\System32\win32u.dll @ 0x75315c30 (jmp dword [0x74bffcd8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ValidateRect : C:\Windows\System32\win32u.dll @ 0x75313140 (jmp dword [0x74bff9c0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCaretBlinkTime : C:\Windows\System32\win32u.dll @ 0x753133a0 (jmp dword [0x74bffce0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EndMenu : C:\Windows\System32\win32u.dll @ 0x75315bb0 (jmp dword [0x74bffd04])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75316760 (jmp dword [0x74bffa74])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetRawInputData : C:\Windows\System32\win32u.dll @ 0x75315f30 (jmp dword [0x74bffc30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RegisterRawInputDevices : C:\Windows\System32\win32u.dll @ 0x753164c0 (jmp dword [0x74bffb0c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCursor : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMenuItemRect : C:\Windows\System32\win32u.dll @ 0x75315e00 (jmp dword [0x74bffc74])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RemoveMenu : C:\Windows\System32\win32u.dll @ 0x75313400 (jmp dword [0x74bffae8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DestroyMenu : C:\Windows\System32\win32u.dll @ 0x75313230 (jmp dword [0x74bffd54])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetFocus : C:\Windows\System32\win32u.dll @ 0x75312990 (jmp dword [0x74bffa8c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetMenuDefaultItem : C:\Windows\System32\win32u.dll @ 0x75313480 (jmp dword [0x74bffa68])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetAncestor : C:\Windows\System32\win32u.dll @ 0x75312f90 (jmp dword [0x74bffcec])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesA : C:\Windows\System32\gdi32full.dll @ 0x75b37280 (jmp dword [0x7494774c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesW : C:\Windows\System32\gdi32full.dll @ 0x75b18460 (jmp dword [0x7494714c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetTextExtentExPointI : C:\Windows\System32\gdi32full.dll @ 0x75b37890 (jmp dword [0x7494719c])
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230830
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!GetFullPathNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bbe80 (jmp dword [0x75a00dcc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!CreateFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d600 (jmp dword [0x75a00db0])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!OffsetViewportOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b12db0 (jmp dword [0x74947088])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b071e0 (jmp dword [0x749470ec])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!EnumFontFamiliesExW : C:\Windows\System32\gdi32full.dll @ 0x75b10f90 (jmp dword [0x74947188])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayEnhMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b04c10 (jmp dword [0x74947bd4])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetWinMetaFileBits : C:\Windows\System32\gdi32full.dll @ 0x75b4e4b0 (jmp dword [0x74947c9c])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b0a230 (jmp dword [0x74947bd8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b13b90 (jmp dword [0x74947754])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b39fa0 (jmp dword [0x749476d8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b3a0a0 (jmp dword [0x74947c44])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!CheckProcessForClipboardAccess : C:\Windows\System32\win32u.dll @ 0x75315910 (jmp dword [0x74bffd9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!SetWindowWord : C:\Windows\System32\win32u.dll @ 0x753132e0 (jmp dword [0x74bffa24])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetAutoRotationState : C:\Windows\System32\win32u.dll @ 0x75315c00 (jmp dword [0x74bffce8])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetCurrentInputMessageSource : C:\Windows\System32\win32u.dll @ 0x75315c70 (jmp dword [0x74bffccc])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!ShutdownBlockReasonDestroy : C:\Windows\System32\win32u.dll @ 0x75316940 (jmp dword [0x74bffa10])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!UnhookWinEvent : C:\Windows\System32\win32u.dll @ 0x753134b0 (jmp dword [0x74bff9ec])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!LockWindowUpdate : C:\Windows\System32\win32u.dll @ 0x753134c0 (jmp dword [0x74bffb6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetShellWindowEx : C:\Windows\System32\win32u.dll @ 0x75316820 (jmp dword [0x74bffa50])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CreateAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75313370 (jmp dword [0x74bffd6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetCoalescableTimer : C:\Windows\System32\win32u.dll @ 0x75312600 (jmp dword [0x74bffaac])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetPointerDevices : C:\Windows\System32\win32u.dll @ 0x75315e80 (jmp dword [0x74bffc50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CloseDesktop : C:\Windows\System32\win32u.dll @ 0x75312ed0 (jmp dword [0x74bffd84])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!OpenInputDesktop : C:\Windows\System32\win32u.dll @ 0x75316350 (jmp dword [0x74bffb50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetWindowBand : C:\Windows\System32\win32u.dll @ 0x75315fd0 (jmp dword [0x74bffc04])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetGestureConfig : C:\Windows\System32\win32u.dll @ 0x753166f0 (jmp dword [0x74bffa88])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetUserObjectInformationW : C:\Windows\System32\win32u.dll @ 0x75312b30 (jmp dword [0x74bffc08])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetProcessWindowStation : C:\Windows\System32\win32u.dll @ 0x753126a0 (jmp dword [0x74bffc38])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetThreadDesktop : C:\Windows\System32\win32u.dll @ 0x75312ca0 (jmp dword [0x74bffc18])
[IAT:Inl] (iexplore.exe @ shell32.dll) gdi32!PlgBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46ae0 (jmp dword [0x749470e4])
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!MaskBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46710 (jmp dword [0x749477e0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75b47870 (jmp dword [0x749470dc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetPixelV : C:\Windows\System32\gdi32full.dll @ 0x75b47210 (jmp dword [0x74947c7c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetCharWidthW : C:\Windows\System32\gdi32full.dll @ 0x75b125d0 (jmp dword [0x7494713c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetNearestColor : C:\Windows\System32\gdi32full.dll @ 0x75b16940 (jmp dword [0x7494777c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetDCEx : C:\Windows\System32\win32u.dll @ 0x75312d90 (jmp dword [0x74bffcc0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetScrollBarInfo : C:\Windows\System32\win32u.dll @ 0x75312da0 (jmp dword [0x74bffc20])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!ShowWindowAsync : C:\Windows\System32\win32u.dll @ 0x75313610 (jmp dword [0x74bffa14])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!IsTopLevelWindow : C:\Windows\System32\win32u.dll @ 0x75316210 (jmp dword [0x74bffb84])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetCaretPos : C:\Windows\System32\win32u.dll @ 0x75315c20 (jmp dword [0x74bffcdc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!InvalidateRgn : C:\Windows\System32\win32u.dll @ 0x753130f0 (jmp dword [0x74bffb98])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!RegisterTouchHitTestingWindow : C:\Windows\System32\win32u.dll @ 0x75316510 (jmp dword [0x74bffaf8])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!DragDetect : C:\Windows\System32\win32u.dll @ 0x75315aa0 (jmp dword [0x74bffd40])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!BlockInput : C:\Windows\System32\win32u.dll @ 0x75315870 (jmp dword [0x74bffdb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!GetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7603b170 (jmp dword [0x75a00d90])
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x777b19d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603e960
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603eed0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comdlg32.dll) user32!ClipCursor : C:\Windows\System32\win32u.dll @ 0x75315960 (jmp dword [0x74bffd88])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!GetCharWidth32W : C:\Windows\System32\gdi32full.dll @ 0x75b36e00 (jmp dword [0x749476f4])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!CreateDiscardableBitmap : C:\Windows\System32\gdi32full.dll @ 0x75b39c30 (jmp dword [0x749472f0])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GetRandomRgn : C:\Windows\System32\gdi32full.dll @ 0x75b15c40 (jmp dword [0x74944300])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GdiDrawStream : C:\Windows\System32\gdi32full.dll @ 0x75b13580 (jmp dword [0x749475d4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!SetBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a890 (jmp dword [0x74947c40])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ExtCreatePen : C:\Windows\System32\gdi32full.dll @ 0x75b18db0 (jmp dword [0x74947530])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!AbortPath : C:\Windows\System32\gdi32full.dll @ 0x75b478f0 (jmp dword [0x7494725c])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!StrokeAndFillPath : C:\Windows\System32\gdi32full.dll @ 0x75b47a70 (jmp dword [0x74947cb4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!CreateSessionMappedDIBSection : C:\Windows\System32\gdi32full.dll @ 0x75b3a710 (jmp dword [0x74947318])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ClearBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a6d0 (jmp dword [0x749472ac])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!CalcMenuBar : C:\Windows\System32\win32u.dll @ 0x75312de0 (jmp dword [0x74bffdac])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!PaintMenuBar : C:\Windows\System32\win32u.dll @ 0x75313340 (jmp dword [0x74bffb48])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!GetMenuBarInfo : C:\Windows\System32\win32u.dll @ 0x75313080 (jmp dword [0x74bffc78])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitOnceInitialize : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x77788520
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!DeleteFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c5f0 (jmp dword [0x75a00cfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SwitchToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x76049e70 (jmp dword [0x75a00cf8])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604a2f0 (jmp dword [0x75a00d04])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertThreadToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c4e0 (jmp dword [0x75a00d0c])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertFiberToThread : C:\Windows\System32\KERNELBASE.dll @ 0x7604de70 (jmp dword [0x75a00d10])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetDiskFreeSpaceW : C:\Windows\System32\KERNELBASE.dll @ 0x760bc140 (jmp dword [0x75a00d74])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl] (iexplore.exe @ mshtml.dll) kernel32!WTSGetActiveConsoleSessionId : C:\Windows\System32\ntdll.dll @ 0x7779fce0 (jmp dword [0x75a019b0])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!CreateHatchBrush : C:\Windows\System32\gdi32full.dll @ 0x75b39d10 (jmp dword [0x74947308])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetFontUnicodeRanges : C:\Windows\System32\gdi32full.dll @ 0x75b1b1c0 (jmp dword [0x74947748])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetGlyphOutlineW : C:\Windows\System32\gdi32full.dll @ 0x75b13080 (jmp dword [0x74947150])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetOutlineTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75aecc70 (jmp dword [0x74947158])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!AddFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3af20 (jmp dword [0x749471b4])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!RemoveFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3c040 (jmp dword [0x74947190])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!EnumObjects : C:\Windows\System32\gdi32full.dll @ 0x75b39d30 (jmp dword [0x74947058])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75315dd0 (jmp dword [0x74bffc84])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetCursorInfo : C:\Windows\System32\win32u.dll @ 0x75315c90 (jmp dword [0x74bffcc8])
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!ChildWindowFromPointEx : C:\Windows\System32\win32u.dll @ 0x75315940 (jmp dword [0x74bffd90])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x777a7480
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetWindowCompositionAttribute : C:\Windows\System32\win32u.dll @ 0x75315fe0 (jmp dword [0x74bffc00])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!UpdateDefaultDesktopThumbnail : C:\Windows\System32\win32u.dll @ 0x75316a40 (jmp dword [0x74bff9d4])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!SetWindowCompositionTransition : C:\Windows\System32\win32u.dll @ 0x753168b0 (jmp dword [0x74bffa3c])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetGuiResources : C:\Windows\System32\win32u.dll @ 0x75315d30 (jmp dword [0x74bffca0])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ msctf.dll) user32!GetInputLocaleInfo : C:\Windows\System32\win32u.dll @ 0x75315d70 (jmp dword [0x74bffc9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!ModifyWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b05a80 (jmp dword [0x749477e8])
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!GetWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b174f0 (jmp dword [0x74947084])
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7777dea0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x777b6750
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x777b6bb0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x777b6be0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x777b6790
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x777bd520
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!SetFilePointerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603a010 (jmp dword [0x75a00e34])
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!DebugBreak : C:\Windows\System32\KERNELBASE.dll @ 0x760b48d0 (jmp dword [0x75a00c88])
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetFileAttributesA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d930 (jmp dword [0x75a00d80])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateDirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x76039b70 (jmp dword [0x75a00dbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!FindFirstFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d1f0 (jmp dword [0x75a00d34])
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x77822cc0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7779e380
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7777def0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x777a7450
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!FatalAppExitA : C:\Windows\System32\KERNELBASE.dll @ 0x760b8c30 (jmp dword [0x75a00a88])
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!SetConsoleCtrlHandler : C:\Windows\System32\KERNELBASE.dll @ 0x7603e350 (jmp dword [0x75a00b84])
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230a10
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!RegisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316480 (jmp dword [0x74bffb18])
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!UnregisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316a10 (jmp dword [0x74bff9e0])
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!MenuItemFromPoint : C:\Windows\System32\win32u.dll @ 0x75316300 (jmp dword [0x74bffb5c])
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!SetConsoleTextAttribute : C:\Windows\System32\KERNELBASE.dll @ 0x76093c80 (jmp dword [0x75a00bf4])
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetConsoleScreenBufferInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76093770 (jmp dword [0x75a00c20])
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EncodeSystemPointer : C:\Windows\System32\ntdll.dll @ 0x777753d0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempFileNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc460 (jmp dword [0x75a00e54])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempPathA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc590 (jmp dword [0x75a00e60])
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!DeleteFileA : C:\Windows\System32\KERNELBASE.dll @ 0x76054340 (jmp dword [0x75a00d3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7602c870
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7603e110
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Inl] (iexplore.exe @ t2embed.dll) gdi32!CreateScalableFontResourceA : C:\Windows\System32\gdi32full.dll @ 0x75b3b2d0 (jmp dword [0x74947310])
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!ReadConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094300 (jmp dword [0x75a00b88])
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetTickCount : C:\Windows\System32\KERNELBASE.dll @ 0x76031940 (call dword [0x75a015dc])
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetNativeSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034cf0 (jmp dword [0x75a015f8])
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetSystemTimeAsFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7601c450 (jmp dword [0x75a0160c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateSemaphoreExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b070 (jmp dword [0x75a01520])
[IAT:Inl] (iexplore.exe) kernel32!SetLastError : C:\Windows\System32\ntdll.dll @ 0x777792b0 (jmp dword [0x75a019e0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetCommandLineW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e140 (jmp dword [0x75a011f8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseSemaphore : C:\Windows\System32\KERNELBASE.dll @ 0x760557c0 (jmp dword [0x75a01568])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringA : C:\Windows\System32\KERNELBASE.dll @ 0x760575e0 (jmp dword [0x75a00c90])
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObject : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae60 (jmp dword [0x75a01580])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseMutex : C:\Windows\System32\KERNELBASE.dll @ 0x76031b00 (jmp dword [0x75a01564])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetLastError : C:\Windows\System32\KERNELBASE.dll @ 0x76029f30 (jmp dword [0x75a00cd0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringW : C:\Windows\System32\KERNELBASE.dll @ 0x760574f0 (jmp dword [0x75a00c94])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObjectEx : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae80 (jmp dword [0x75a01584])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OpenSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b330 (jmp dword [0x75a01560])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CloseHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7602ad80 (jmp dword [0x75a00eac])
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateMutexExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b960 (jmp dword [0x75a01528])
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetProcessHeap : C:\Windows\System32\KERNELBASE.dll @ 0x76031c20 (jmp dword [0x75a00ec8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!IsDebuggerPresent : C:\Windows\System32\KERNELBASE.dll @ 0x7603dda0 (jmp dword [0x75a00c8c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!Sleep : C:\Windows\System32\KERNELBASE.dll @ 0x76032d70 (jmp dword [0x75a00a6c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetStartupInfoW : C:\Windows\System32\KERNELBASE.dll @ 0x7603a600 (jmp dword [0x75a012d8])
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x76017e20
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x760583d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SleepEx : C:\Windows\System32\KERNELBASE.dll @ 0x76032d90 (jmp dword [0x75a01578])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b560 (jmp dword [0x75a01534])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetThreadUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76048d70 (jmp dword [0x75a00fd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!WriteFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029360 (jmp dword [0x75a00e48])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFilePointer : C:\Windows\System32\KERNELBASE.dll @ 0x76033440 (jmp dword [0x75a00e30])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a5c0 (jmp dword [0x75a00dac])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesExW : C:\Windows\System32\KERNELBASE.dll @ 0x76039140 (jmp dword [0x75a00d88])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DeleteFileW : C:\Windows\System32\KERNELBASE.dll @ 0x76055330 (jmp dword [0x75a00d18])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSizeEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603c060 (jmp dword [0x75a00d98])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CompareFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x760390b0 (jmp dword [0x75a00dc0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetVolumePathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76050e20 (jmp dword [0x75a00df4])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!AreFileApisANSI : C:\Windows\System32\KERNELBASE.dll @ 0x7604c350 (jmp dword [0x75a009c4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFullPathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76039070 (jmp dword [0x75a00dd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c7a0 (jmp dword [0x75a00d8c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b4a0 (jmp dword [0x75a01524])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76033d80 (jmp dword [0x75a01570])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!ResetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76035530 (jmp dword [0x75a0156c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x76049b40 (jmp dword [0x75a00d9c])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DuplicateHandle : C:\Windows\System32\KERNELBASE.dll @ 0x760361d0 (jmp dword [0x75a00eb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x777b4020
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778ac30
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778acf0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!RaiseException : C:\Windows\System32\KERNELBASE.dll @ 0x7603a990 (jmp dword [0x75a00cbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7604b4e0 (jmp dword [0x75a00e2c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindClose : C:\Windows\System32\KERNELBASE.dll @ 0x760350a0 (jmp dword [0x75a00d24])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindNextFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a1f0 (jmp dword [0x75a00d58])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindFirstFileExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c090 (jmp dword [0x75a00dc4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSize : C:\Windows\System32\KERNELBASE.dll @ 0x76034c80 (jmp dword [0x75a00d94])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!ReadFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029d40 (jmp dword [0x75a00e0c])
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetCommandLineA : C:\Windows\System32\KERNELBASE.dll @ 0x7603e210 (jmp dword [0x75a011fc])
[IAT:Inl] (iexplore.exe @ eplgIE.dll) kernel32!RtlUnwind : C:\Windows\System32\ntdll.dll @ 0x777af000 (jmp dword [0x75a014b8])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetACP : C:\Windows\System32\KERNELBASE.dll @ 0x76039cc0 (jmp dword [0x75a01050])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetOEMCP : C:\Windows\System32\KERNELBASE.dll @ 0x76058bc0 (jmp dword [0x75a01074])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!TlsAlloc : C:\Windows\System32\KERNELBASE.dll @ 0x760397e0 (jmp dword [0x75a01278])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetFileType : C:\Windows\System32\KERNELBASE.dll @ 0x76036110 (jmp dword [0x75a00da0])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetEnvironmentStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76033560 (jmp dword [0x75a01214])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleCP : C:\Windows\System32\KERNELBASE.dll @ 0x760936e0 (jmp dword [0x75a00bac])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleMode : C:\Windows\System32\KERNELBASE.dll @ 0x7601fcf0 (jmp dword [0x75a00ba4])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!WriteConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094410 (jmp dword [0x75a00b78])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FlushFileBuffers : C:\Windows\System32\KERNELBASE.dll @ 0x76057fb0 (jmp dword [0x75a00d64])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetObjectW : C:\Windows\System32\gdi32full.dll @ 0x75ae2540 (jmp dword [0x74947018])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b05e80 (jmp dword [0x74947050])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetBitmapBitsSize : C:\Windows\System32\gdi32full.dll @ 0x75ae29c0 (jmp dword [0x74947628])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75ae4ee0 (jmp dword [0x74947100])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiValidateHandle : C:\Windows\System32\gdi32full.dll @ 0x75ae2490 (jmp dword [0x749476c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetMapMode : C:\Windows\System32\gdi32full.dll @ 0x75b072a0 (jmp dword [0x749470fc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetHFONT : C:\Windows\System32\gdi32full.dll @ 0x75b12980 (jmp dword [0x74947758])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b05f30 (jmp dword [0x749470a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDCOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b13c00 (jmp dword [0x7494702c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiFixUpHandle : C:\Windows\System32\gdi32full.dll @ 0x75b0cac0 (jmp dword [0x7494761c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiPrinterThunk : C:\Windows\System32\gdi32full.dll @ 0x75b4c7c0 (jmp dword [0x74947690])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiLoadType1Fonts : C:\Windows\System32\gdi32full.dll @ 0x75b3bb90 (jmp dword [0x74947674])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiAddFontResourceW : C:\Windows\System32\gdi32full.dll @ 0x75b3ba60 (jmp dword [0x7494757c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiProcessSetup : C:\Windows\System32\gdi32full.dll @ 0x75ae4090 (jmp dword [0x74947694])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiDllInitialize : C:\Windows\System32\gdi32full.dll @ 0x75ae3ea0 (jmp dword [0x749442d8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnableEUDC : C:\Windows\System32\gdi32full.dll @ 0x75b1c570 (jmp dword [0x74947444])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertBitmapV5 : C:\Windows\System32\gdi32full.dll @ 0x75b3e180 (jmp dword [0x7494759c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertToDevmodeW : C:\Windows\System32\gdi32full.dll @ 0x75b39e20 (jmp dword [0x749475bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!MirrorRgn : C:\Windows\System32\gdi32full.dll @ 0x75b3a3b0 (jmp dword [0x749477e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b174c0 (jmp dword [0x749476dc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b06e80 (jmp dword [0x749470a4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!ExcludeClipRect : C:\Windows\System32\gdi32full.dll @ 0x75b1abd0 (jmp dword [0x74947008])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CreateEllipticRgn : C:\Windows\System32\gdi32full.dll @ 0x75b39c40 (jmp dword [0x749472f4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!PolyPatBlt : C:\Windows\System32\gdi32full.dll @ 0x75b10850 (jmp dword [0x74947be4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetTextCharacterExtra : C:\Windows\System32\gdi32full.dll @ 0x75b07a40 (jmp dword [0x749471bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayoutWidth : C:\Windows\System32\gdi32full.dll @ 0x75b18d20 (jmp dword [0x74947c70])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertAndCheckDC : C:\Windows\System32\gdi32full.dll @ 0x75b16730 (jmp dword [0x74947594])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b16910 (jmp dword [0x74947c4c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyEnhMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b4dd60 (jmp dword [0x749472c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b44a70 (jmp dword [0x749472d0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharsetInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1b1d0 (jmp dword [0x749477ac])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!QueryFontAssocStatus : C:\Windows\System32\gdi32full.dll @ 0x75b196e0 (jmp dword [0x74947bfc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharWidthInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1ca20 (jmp dword [0x74947704])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceW : C:\Windows\System32\gdi32full.dll @ 0x75ae8930 (jmp dword [0x74947174])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsW : C:\Windows\System32\gdi32full.dll @ 0x75b15a30 (jmp dword [0x74947134])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsA : C:\Windows\System32\gdi32full.dll @ 0x75b36d40 (jmp dword [0x749476e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b076a0 (jmp dword [0x749470e0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceAliasW : C:\Windows\System32\gdi32full.dll @ 0x75ae8030 (jmp dword [0x749477b8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnumFontsW : C:\Windows\System32\gdi32full.dll @ 0x75b10e80 (jmp dword [0x749471a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b51010 (jmp dword [0x749475c0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b51030 (jmp dword [0x749475c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b50f20 (jmp dword [0x749475a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b50f90 (jmp dword [0x749475b0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75afd6e0 (jmp dword [0x74947178])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!TextOutW : C:\Windows\System32\gdi32full.dll @ 0x75b47680 (jmp dword [0x74947184])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetWindowExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecf90 (jmp dword [0x749470f0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetViewportExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecec0 (jmp dword [0x749477c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBkMode : C:\Windows\System32\gdi32full.dll @ 0x75b043f0 (jmp dword [0x7494706c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCharDimensions : C:\Windows\System32\gdi32full.dll @ 0x75b13cb0 (jmp dword [0x7494762c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharset : C:\Windows\System32\gdi32full.dll @ 0x75b17c90 (jmp dword [0x749471a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCodePage : C:\Windows\System32\gdi32full.dll @ 0x75b11760 (jmp dword [0x74947630])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextExtentPointW : C:\Windows\System32\gdi32full.dll @ 0x75afaf60 (jmp dword [0x74947194])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!OffsetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b14060 (jmp dword [0x749470e8])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!InvalidateRect : C:\Windows\System32\win32u.dll @ 0x753124c0 (jmp dword [0x74bffb9c])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetKeyboardLayoutList : C:\Windows\System32\win32u.dll @ 0x75312a00 (jmp dword [0x74bffc8c])
[IAT:Addr(Microsoft)] (iexplore.exe @ gdi32full.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetDC : C:\Windows\System32\win32u.dll @ 0x75312520 (jmp dword [0x74bffcc4])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetForegroundWindow : C:\Windows\System32\win32u.dll @ 0x75312840 (jmp dword [0x74bffcac])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75312bf0 (jmp dword [0x74bffc88])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!DestroyWindow : C:\Windows\System32\win32u.dll @ 0x75312e40 (jmp dword [0x74bffd50])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!ShowWindow : C:\Windows\System32\win32u.dll @ 0x753129f0 (jmp dword [0x74bffa18])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!EndPaint : C:\Windows\System32\win32u.dll @ 0x75312610 (jmp dword [0x74bffd00])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!BeginPaint : C:\Windows\System32\win32u.dll @ 0x753125f0 (jmp dword [0x74bffdb8])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetWindowPos : C:\Windows\System32\win32u.dll @ 0x753126c0 (jmp dword [0x74bffa2c])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetCapture : C:\Windows\System32\win32u.dll @ 0x75312910 (jmp dword [0x74bffab8])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetFocus : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcessMitigationPolicy : C:\Windows\System32\KERNELBASE.dll @ 0x7603af60
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetThreadLocale : C:\Windows\System32\KERNELBASE.dll @ 0x7603b480 (jmp dword [0x75a01060])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetSystemDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c630 (jmp dword [0x75a01064])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl] (iexplore.exe @ imm32.dll) kernel32!RtlCaptureContext : C:\Windows\System32\ntdll.dll @ 0x777d2e00 (jmp dword [0x75a014c4])
[IAT:Inl] (iexplore.exe @ imm32.dll) gdi32!GetTextExtentPoint32W : C:\Windows\System32\gdi32full.dll @ 0x75afe460 (jmp dword [0x74947198])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CopyFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7603f280 (jmp dword [0x75a00ea4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempPathW : C:\Windows\System32\KERNELBASE.dll @ 0x7603d040 (jmp dword [0x75a00de4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempFileNameW : C:\Windows\System32\KERNELBASE.dll @ 0x7604f170 (jmp dword [0x75a00ddc])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bb760
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bba70
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b3d0 (jmp dword [0x75a0155c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034d50 (jmp dword [0x75a01600])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c490 (jmp dword [0x75a01030])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x76035480 (jmp dword [0x75a01604])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionAndSpinCount : C:\Windows\System32\KERNELBASE.dll @ 0x76034c60 (jmp dword [0x75a0154c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604fe20 (jmp dword [0x75a00e38])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetFinalPathNameByHandleW : C:\Windows\System32\KERNELBASE.dll @ 0x76046b60 (jmp dword [0x75a00dc8])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLocalTime : C:\Windows\System32\KERNELBASE.dll @ 0x760344b0 (jmp dword [0x75a015f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x760345d0 (jmp dword [0x75a01668])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToLocalFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604a210 (jmp dword [0x75a00d20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc440 (jmp dword [0x75a016cc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateMutexA : C:\Windows\System32\KERNELBASE.dll @ 0x76051fb0 (jmp dword [0x75a01530])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjects : C:\Windows\System32\KERNELBASE.dll @ 0x76031c30 (jmp dword [0x75a015b8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x76057af0 (jmp dword [0x75a00e28])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b670 (jmp dword [0x75a01544])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b040 (jmp dword [0x75a015b4])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034ec0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CancelWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045b70 (jmp dword [0x75a01540])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76050660 (jmp dword [0x75a01034])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76047db0 (jmp dword [0x75a01068])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjectsEx : C:\Windows\System32\KERNELBASE.dll @ 0x76031c60 (jmp dword [0x75a0157c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045120 (jmp dword [0x75a01574])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c070 (jmp dword [0x75a00d44])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDriveTypeW : C:\Windows\System32\KERNELBASE.dll @ 0x76035950 (jmp dword [0x75a00d7c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventA : C:\Windows\System32\KERNELBASE.dll @ 0x7602b5d0 (jmp dword [0x75a0153c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateFile2 : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6a0 (jmp dword [0x75a00db4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76057ee0 (jmp dword [0x75a016d8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LocalFileTimeToFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604edf0 (jmp dword [0x75a00dfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetEndOfFile : C:\Windows\System32\KERNELBASE.dll @ 0x7603d520 (jmp dword [0x75a00e20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDiskFreeSpaceExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603bbe0 (jmp dword [0x75a00d70])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!UnlockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6d0 (jmp dword [0x75a00e40])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604cb60 (jmp dword [0x75a00e00])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLogicalDriveStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76059010 (jmp dword [0x75a00dd4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!QueryDosDeviceW : C:\Windows\System32\KERNELBASE.dll @ 0x76056b40 (jmp dword [0x75a00e08])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetVersion : C:\Windows\System32\KERNELBASE.dll @ 0x76057ca0 (jmp dword [0x75a01610])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x7603e150 (jmp dword [0x75a00a3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034fa0 (jmp dword [0x75a01550])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!ReleaseActCtx : C:\Windows\System32\KERNELBASE.dll @ 0x76057c50 (jmp dword [0x75a014f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76034390 (jmp dword [0x75a00a40])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b720 (jmp dword [0x75a01558])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!RemoveDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e600 (jmp dword [0x75a00e1c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76039bb0 (jmp dword [0x75a00db8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b43e80 (jmp dword [0x7494704c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiTransparentBlt : C:\Windows\System32\gdi32full.dll @ 0x75b182f0 (jmp dword [0x74947108])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiGradientFill : C:\Windows\System32\gdi32full.dll @ 0x75b134a0 (jmp dword [0x7494710c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiAlphaBlend : C:\Windows\System32\gdi32full.dll @ 0x75b107c0 (jmp dword [0x749470cc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b0cb10 (jmp dword [0x74947104])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateHalftonePalette : C:\Windows\System32\gdi32full.dll @ 0x75b1b1b0 (jmp dword [0x74947304])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!PtInRegion : C:\Windows\System32\gdi32full.dll @ 0x75b3a610 (jmp dword [0x7494436c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateFontW : C:\Windows\System32\gdi32full.dll @ 0x75b16130 (jmp dword [0x749471b8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiFlush : C:\Windows\System32\gdi32full.dll @ 0x75b13800 (jmp dword [0x74947060])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCPenColor : C:\Windows\System32\gdi32full.dll @ 0x75b441a0 (jmp dword [0x74947c5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b44000 (jmp dword [0x7494701c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetTextExtentExPointW : C:\Windows\System32\gdi32full.dll @ 0x75b17ea0 (jmp dword [0x74947168])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateDIBPatternBrushPt : C:\Windows\System32\gdi32full.dll @ 0x75b39c00 (jmp dword [0x74947124])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!MoveWindow : C:\Windows\System32\win32u.dll @ 0x75312a50 (jmp dword [0x74bffb58])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WaitMessage : C:\Windows\System32\win32u.dll @ 0x75312540 (jmp dword [0x74bff9b4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackPopupMenuEx : C:\Windows\System32\win32u.dll @ 0x753169b0 (jmp dword [0x74bff9f4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DeleteMenu : C:\Windows\System32\win32u.dll @ 0x75313030 (jmp dword [0x74bffd5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!CopyAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75312740 (jmp dword [0x74bffd70])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!KillTimer : C:\Windows\System32\win32u.dll @ 0x75312630 (jmp dword [0x74bffb78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetDoubleClickTime : C:\Windows\System32\win32u.dll @ 0x75312fd0 (jmp dword [0x74bffcb0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WindowFromPoint : C:\Windows\System32\win32u.dll @ 0x753125c0 (jmp dword [0x74bff9ac])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageTime : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!AttachThreadInput : C:\Windows\System32\win32u.dll @ 0x75313320 (jmp dword [0x74bffdbc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetSystemMenu : C:\Windows\System32\win32u.dll @ 0x75312a80 (jmp dword [0x74bffc1c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!FlashWindowEx : C:\Windows\System32\win32u.dll @ 0x75315bd0 (jmp dword [0x74bffcf4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowDC : C:\Windows\System32\win32u.dll @ 0x75312ab0 (jmp dword [0x74bffbf8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackMouseEvent : C:\Windows\System32\win32u.dll @ 0x75313210 (jmp dword [0x74bff9f8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SendInput : C:\Windows\System32\win32u.dll @ 0x75312c90 (jmp dword [0x74bffad8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetGUIThreadInfo : C:\Windows\System32\win32u.dll @ 0x75313450 (jmp dword [0x74bffca8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x753131b0 (jmp dword [0x74bffbe8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetTitleBarInfo : C:\Windows\System32\win32u.dll @ 0x75312d60 (jmp dword [0x74bffc14])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75313350 (jmp dword [0x74bffa78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!PrintWindow : C:\Windows\System32\win32u.dll @ 0x753163a0 (jmp dword [0x74bffb38])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetComboBoxInfo : C:\Windows\System32\win32u.dll @ 0x75315c60 (jmp dword [0x74bffcd0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RedrawWindow : C:\Windows\System32\win32u.dll @ 0x753125b0 (jmp dword [0x74bffb24])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageExtraInfo : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ShowScrollBar : C:\Windows\System32\win32u.dll @ 0x75312850 (jmp dword [0x74bffa20])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x75313280 (jmp dword [0x74bffa30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75313260 (jmp dword [0x74bffac8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ChangeWindowMessageFilterEx : C:\Windows\System32\win32u.dll @ 0x753158f0 (jmp dword [0x74bffda0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EnumDisplayMonitors : C:\Windows\System32\win32u.dll @ 0x75312920 (jmp dword [0x74bffcfc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetClipCursor : C:\Windows\System32\win32u.dll @ 0x75315c30 (jmp dword [0x74bffcd8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ValidateRect : C:\Windows\System32\win32u.dll @ 0x75313140 (jmp dword [0x74bff9c0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCaretBlinkTime : C:\Windows\System32\win32u.dll @ 0x753133a0 (jmp dword [0x74bffce0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EndMenu : C:\Windows\System32\win32u.dll @ 0x75315bb0 (jmp dword [0x74bffd04])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75316760 (jmp dword [0x74bffa74])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetRawInputData : C:\Windows\System32\win32u.dll @ 0x75315f30 (jmp dword [0x74bffc30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RegisterRawInputDevices : C:\Windows\System32\win32u.dll @ 0x753164c0 (jmp dword [0x74bffb0c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCursor : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMenuItemRect : C:\Windows\System32\win32u.dll @ 0x75315e00 (jmp dword [0x74bffc74])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RemoveMenu : C:\Windows\System32\win32u.dll @ 0x75313400 (jmp dword [0x74bffae8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DestroyMenu : C:\Windows\System32\win32u.dll @ 0x75313230 (jmp dword [0x74bffd54])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetFocus : C:\Windows\System32\win32u.dll @ 0x75312990 (jmp dword [0x74bffa8c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetMenuDefaultItem : C:\Windows\System32\win32u.dll @ 0x75313480 (jmp dword [0x74bffa68])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetAncestor : C:\Windows\System32\win32u.dll @ 0x75312f90 (jmp dword [0x74bffcec])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesA : C:\Windows\System32\gdi32full.dll @ 0x75b37280 (jmp dword [0x7494774c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesW : C:\Windows\System32\gdi32full.dll @ 0x75b18460 (jmp dword [0x7494714c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetTextExtentExPointI : C:\Windows\System32\gdi32full.dll @ 0x75b37890 (jmp dword [0x7494719c])
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230830
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!GetFullPathNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bbe80 (jmp dword [0x75a00dcc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!CreateFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d600 (jmp dword [0x75a00db0])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!OffsetViewportOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b12db0 (jmp dword [0x74947088])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b071e0 (jmp dword [0x749470ec])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!EnumFontFamiliesExW : C:\Windows\System32\gdi32full.dll @ 0x75b10f90 (jmp dword [0x74947188])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayEnhMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b04c10 (jmp dword [0x74947bd4])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetWinMetaFileBits : C:\Windows\System32\gdi32full.dll @ 0x75b4e4b0 (jmp dword [0x74947c9c])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b0a230 (jmp dword [0x74947bd8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b13b90 (jmp dword [0x74947754])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b39fa0 (jmp dword [0x749476d8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b3a0a0 (jmp dword [0x74947c44])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!CheckProcessForClipboardAccess : C:\Windows\System32\win32u.dll @ 0x75315910 (jmp dword [0x74bffd9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!SetWindowWord : C:\Windows\System32\win32u.dll @ 0x753132e0 (jmp dword [0x74bffa24])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetAutoRotationState : C:\Windows\System32\win32u.dll @ 0x75315c00 (jmp dword [0x74bffce8])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetCurrentInputMessageSource : C:\Windows\System32\win32u.dll @ 0x75315c70 (jmp dword [0x74bffccc])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!ShutdownBlockReasonDestroy : C:\Windows\System32\win32u.dll @ 0x75316940 (jmp dword [0x74bffa10])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!UnhookWinEvent : C:\Windows\System32\win32u.dll @ 0x753134b0 (jmp dword [0x74bff9ec])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!LockWindowUpdate : C:\Windows\System32\win32u.dll @ 0x753134c0 (jmp dword [0x74bffb6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetShellWindowEx : C:\Windows\System32\win32u.dll @ 0x75316820 (jmp dword [0x74bffa50])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CreateAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75313370 (jmp dword [0x74bffd6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetCoalescableTimer : C:\Windows\System32\win32u.dll @ 0x75312600 (jmp dword [0x74bffaac])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetPointerDevices : C:\Windows\System32\win32u.dll @ 0x75315e80 (jmp dword [0x74bffc50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CloseDesktop : C:\Windows\System32\win32u.dll @ 0x75312ed0 (jmp dword [0x74bffd84])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!OpenInputDesktop : C:\Windows\System32\win32u.dll @ 0x75316350 (jmp dword [0x74bffb50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetWindowBand : C:\Windows\System32\win32u.dll @ 0x75315fd0 (jmp dword [0x74bffc04])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetGestureConfig : C:\Windows\System32\win32u.dll @ 0x753166f0 (jmp dword [0x74bffa88])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetUserObjectInformationW : C:\Windows\System32\win32u.dll @ 0x75312b30 (jmp dword [0x74bffc08])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetProcessWindowStation : C:\Windows\System32\win32u.dll @ 0x753126a0 (jmp dword [0x74bffc38])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetThreadDesktop : C:\Windows\System32\win32u.dll @ 0x75312ca0 (jmp dword [0x74bffc18])
[IAT:Inl] (iexplore.exe @ shell32.dll) gdi32!PlgBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46ae0 (jmp dword [0x749470e4])
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!MaskBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46710 (jmp dword [0x749477e0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75b47870 (jmp dword [0x749470dc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetPixelV : C:\Windows\System32\gdi32full.dll @ 0x75b47210 (jmp dword [0x74947c7c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetCharWidthW : C:\Windows\System32\gdi32full.dll @ 0x75b125d0 (jmp dword [0x7494713c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetNearestColor : C:\Windows\System32\gdi32full.dll @ 0x75b16940 (jmp dword [0x7494777c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetDCEx : C:\Windows\System32\win32u.dll @ 0x75312d90 (jmp dword [0x74bffcc0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetScrollBarInfo : C:\Windows\System32\win32u.dll @ 0x75312da0 (jmp dword [0x74bffc20])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!ShowWindowAsync : C:\Windows\System32\win32u.dll @ 0x75313610 (jmp dword [0x74bffa14])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!IsTopLevelWindow : C:\Windows\System32\win32u.dll @ 0x75316210 (jmp dword [0x74bffb84])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetCaretPos : C:\Windows\System32\win32u.dll @ 0x75315c20 (jmp dword [0x74bffcdc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!InvalidateRgn : C:\Windows\System32\win32u.dll @ 0x753130f0 (jmp dword [0x74bffb98])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!RegisterTouchHitTestingWindow : C:\Windows\System32\win32u.dll @ 0x75316510 (jmp dword [0x74bffaf8])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!DragDetect : C:\Windows\System32\win32u.dll @ 0x75315aa0 (jmp dword [0x74bffd40])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!BlockInput : C:\Windows\System32\win32u.dll @ 0x75315870 (jmp dword [0x74bffdb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!GetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7603b170 (jmp dword [0x75a00d90])
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x777b19d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603e960
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603eed0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comdlg32.dll) user32!ClipCursor : C:\Windows\System32\win32u.dll @ 0x75315960 (jmp dword [0x74bffd88])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!GetCharWidth32W : C:\Windows\System32\gdi32full.dll @ 0x75b36e00 (jmp dword [0x749476f4])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!CreateDiscardableBitmap : C:\Windows\System32\gdi32full.dll @ 0x75b39c30 (jmp dword [0x749472f0])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GetRandomRgn : C:\Windows\System32\gdi32full.dll @ 0x75b15c40 (jmp dword [0x74944300])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GdiDrawStream : C:\Windows\System32\gdi32full.dll @ 0x75b13580 (jmp dword [0x749475d4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!SetBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a890 (jmp dword [0x74947c40])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ExtCreatePen : C:\Windows\System32\gdi32full.dll @ 0x75b18db0 (jmp dword [0x74947530])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!AbortPath : C:\Windows\System32\gdi32full.dll @ 0x75b478f0 (jmp dword [0x7494725c])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!StrokeAndFillPath : C:\Windows\System32\gdi32full.dll @ 0x75b47a70 (jmp dword [0x74947cb4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!CreateSessionMappedDIBSection : C:\Windows\System32\gdi32full.dll @ 0x75b3a710 (jmp dword [0x74947318])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ClearBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a6d0 (jmp dword [0x749472ac])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!CalcMenuBar : C:\Windows\System32\win32u.dll @ 0x75312de0 (jmp dword [0x74bffdac])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!PaintMenuBar : C:\Windows\System32\win32u.dll @ 0x75313340 (jmp dword [0x74bffb48])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!GetMenuBarInfo : C:\Windows\System32\win32u.dll @ 0x75313080 (jmp dword [0x74bffc78])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitOnceInitialize : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x77788520
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!DeleteFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c5f0 (jmp dword [0x75a00cfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SwitchToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x76049e70 (jmp dword [0x75a00cf8])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604a2f0 (jmp dword [0x75a00d04])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertThreadToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c4e0 (jmp dword [0x75a00d0c])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertFiberToThread : C:\Windows\System32\KERNELBASE.dll @ 0x7604de70 (jmp dword [0x75a00d10])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetDiskFreeSpaceW : C:\Windows\System32\KERNELBASE.dll @ 0x760bc140 (jmp dword [0x75a00d74])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl] (iexplore.exe @ mshtml.dll) kernel32!WTSGetActiveConsoleSessionId : C:\Windows\System32\ntdll.dll @ 0x7779fce0 (jmp dword [0x75a019b0])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!CreateHatchBrush : C:\Windows\System32\gdi32full.dll @ 0x75b39d10 (jmp dword [0x74947308])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetFontUnicodeRanges : C:\Windows\System32\gdi32full.dll @ 0x75b1b1c0 (jmp dword [0x74947748])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetGlyphOutlineW : C:\Windows\System32\gdi32full.dll @ 0x75b13080 (jmp dword [0x74947150])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetOutlineTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75aecc70 (jmp dword [0x74947158])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!AddFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3af20 (jmp dword [0x749471b4])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!RemoveFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3c040 (jmp dword [0x74947190])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!EnumObjects : C:\Windows\System32\gdi32full.dll @ 0x75b39d30 (jmp dword [0x74947058])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75315dd0 (jmp dword [0x74bffc84])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetCursorInfo : C:\Windows\System32\win32u.dll @ 0x75315c90 (jmp dword [0x74bffcc8])
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!ChildWindowFromPointEx : C:\Windows\System32\win32u.dll @ 0x75315940 (jmp dword [0x74bffd90])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x777a7480
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetWindowCompositionAttribute : C:\Windows\System32\win32u.dll @ 0x75315fe0 (jmp dword [0x74bffc00])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!UpdateDefaultDesktopThumbnail : C:\Windows\System32\win32u.dll @ 0x75316a40 (jmp dword [0x74bff9d4])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!SetWindowCompositionTransition : C:\Windows\System32\win32u.dll @ 0x753168b0 (jmp dword [0x74bffa3c])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetGuiResources : C:\Windows\System32\win32u.dll @ 0x75315d30 (jmp dword [0x74bffca0])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ msctf.dll) user32!GetInputLocaleInfo : C:\Windows\System32\win32u.dll @ 0x75315d70 (jmp dword [0x74bffc9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!SetFilePointerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603a010 (jmp dword [0x75a00e34])
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!DebugBreak : C:\Windows\System32\KERNELBASE.dll @ 0x760b48d0 (jmp dword [0x75a00c88])
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetFileAttributesA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d930 (jmp dword [0x75a00d80])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateDirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x76039b70 (jmp dword [0x75a00dbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!FindFirstFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d1f0 (jmp dword [0x75a00d34])
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x77822cc0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7779e380
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7777def0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x777a7450
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!FatalAppExitA : C:\Windows\System32\KERNELBASE.dll @ 0x760b8c30 (jmp dword [0x75a00a88])
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!SetConsoleCtrlHandler : C:\Windows\System32\KERNELBASE.dll @ 0x7603e350 (jmp dword [0x75a00b84])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!ModifyWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b05a80 (jmp dword [0x749477e8])
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!GetWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b174f0 (jmp dword [0x74947084])
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7777dea0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x777b6750
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x777b6bb0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x777b6be0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x777b6790
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x777bd520
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!SetConsoleTextAttribute : C:\Windows\System32\KERNELBASE.dll @ 0x76093c80 (jmp dword [0x75a00bf4])
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetConsoleScreenBufferInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76093770 (jmp dword [0x75a00c20])
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EncodeSystemPointer : C:\Windows\System32\ntdll.dll @ 0x777753d0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!RegisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316480 (jmp dword [0x74bffb18])
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!UnregisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316a10 (jmp dword [0x74bff9e0])
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!MenuItemFromPoint : C:\Windows\System32\win32u.dll @ 0x75316300 (jmp dword [0x74bffb5c])
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempFileNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc460 (jmp dword [0x75a00e54])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempPathA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc590 (jmp dword [0x75a00e60])
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!DeleteFileA : C:\Windows\System32\KERNELBASE.dll @ 0x76054340 (jmp dword [0x75a00d3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7602c870
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7603e110
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Inl] (iexplore.exe @ t2embed.dll) gdi32!CreateScalableFontResourceA : C:\Windows\System32\gdi32full.dll @ 0x75b3b2d0 (jmp dword [0x74947310])
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230a10

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0:  +++++
--- User ---
[MBR] f86f4a6d732d5d11731309772e1fbe7f
[BSP] 2bf3dd60e501e1f0f760c942b8d1b006 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1023 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2097152 | Size: 360 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2834432 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 3096576 | Size: 1886686 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 3867029504 | Size: 450 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 3867951104 | Size: 19076 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1:  +++++
--- User ---
[MBR] 1c42ac96cea7b70222a78c22ed7f378f
[BSP] 6f61b52460ecc86ec118b4d775eee70e : Unknown|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x6e) [VISIBLE] Offset (sectors): 1948285285 | Size: 831044 MB
3 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 28049408 | Size: 0 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )


  • 0






Similar Topics


Also tagged with one or more of these keywords: Malware, unknown virus

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP