Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Admin tools all unavailable, seemingly fake dropbox and a few other pr

Malware unknown virus

  • Please log in to reply

#31
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

This is a redo of the Rogue Killer this am??? Not sure if it's b/c I disabled firewall and anti for the scan this am, as well as all day after I had run this one?

 

 

RogueKiller V12.11.6.0 (x64) [Jul 10 2017] (Premium) by Adlice Software
mail : http://www.adlice.com/contact/
Feedback : https://forum.adlice.com
Website : http://www.adlice.co...ad/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 10 (10.0.14393) 64 bits version
Started in : Normal mode
User : AIRWORX 2 [Administrator]
Started from : C:\Program Files\RogueKiller\RogueKiller64.exe
Mode : Scan -- Date : 07/13/2017 05:20:32 (Duration : 01:09:23)

¤¤¤ Processes : 0 ¤¤¤

¤¤¤ Registry : 0 ¤¤¤

¤¤¤ Tasks : 0 ¤¤¤

¤¤¤ Files : 0 ¤¤¤

¤¤¤ WMI : 0 ¤¤¤

¤¤¤ Hosts File : 0 ¤¤¤

¤¤¤ Antirootkit : 2159 (Driver: Loaded) ¤¤¤
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE[0] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE_NAMED_PIPE[1] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CLOSE[2] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_READ[3] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_WRITE[4] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_INFORMATION[5] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_INFORMATION[6] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_EA[7] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_EA[8] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_FLUSH_BUFFERS[9] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_VOLUME_INFORMATION[10] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_VOLUME_INFORMATION[11] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DIRECTORY_CONTROL[12] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_FILE_SYSTEM_CONTROL[13] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DEVICE_CONTROL[14] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_INTERNAL_DEVICE_CONTROL[15] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SHUTDOWN[16] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_LOCK_CONTROL[17] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CLEANUP[18] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_CREATE_MAILSLOT[19] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_SECURITY[20] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_SECURITY[21] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_POWER[22] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SYSTEM_CONTROL[23] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_DEVICE_CHANGE[24] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_QUERY_QUOTA[25] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_SET_QUOTA[26] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\disk - IRP_MJ_PNP[27] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b60004f90
[IRP:Addr(Microsoft)] \Driver\disk - DriverUnload[29] : C:\Windows\System32\drivers\Classpnp.sys @ 0xfffff80b6004d210
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_CREATE_NAMED_PIPE[1] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_WRITE[4] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_INFORMATION[5] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_INFORMATION[6] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_EA[7] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_EA[8] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_VOLUME_INFORMATION[10] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_VOLUME_INFORMATION[11] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_DIRECTORY_CONTROL[12] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_FILE_SYSTEM_CONTROL[13] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SHUTDOWN[16] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_LOCK_CONTROL[17] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_CREATE_MAILSLOT[19] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_SECURITY[20] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_SECURITY[21] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_DEVICE_CHANGE[24] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_QUERY_QUOTA[25] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IRP:Addr(Microsoft)] \Driver\kbdclass - IRP_MJ_SET_QUOTA[26] : C:\Windows\System32\ntoskrnl.exe @ 0xfffff800ca763b60
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!ParseApplicationUserModelId : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5f870
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!FindPackagesByPackageFamily : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5f3d0
[IAT:Addr(Microsoft)] (explorer.exe) kernel32!GetPackagesByPackageFamily : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5d860
[IAT:Addr] (explorer.exe) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ shell32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shell32.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5180
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c4230
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c1900
[IAT:Addr] (explorer.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfeb0
[IAT:Addr] (explorer.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ imm32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ msctf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ ole32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ comctl32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ SndVolSSO.DLL) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ oleacc.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ explorerframe.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ explorerframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ twinui.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ HPSFTaskbar.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Windows.UI.Immersive.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Windows.UI.Immersive.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!CloseState : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5dda0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!OpenStateExplicit : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5dde0
[IAT:Addr(Microsoft)] (explorer.exe @ AboveLockAppHost.dll) kernel32!GetSystemAppDataKey : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5e210
[IAT:Addr] (explorer.exe @ ntshrui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (explorer.exe @ aticfx64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ aticfx64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (explorer.exe @ atiuxp64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ atiuxp64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr(Microsoft)] (explorer.exe @ atidxx64.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b88900
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d37b0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dd490
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (explorer.exe @ atidxx64.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ atidxx64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ atidxx64.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr(Microsoft)] (explorer.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61c50
[IAT:Addr(Microsoft)] (explorer.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ mscoree.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mscoreei.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mscoreei.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!GetCurrentProcessorNumber : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615cc0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!FlushProcessWriteBuffers : C:\Windows\System32\ntdll.dll @ 0x7ffaeb617c80
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!AddVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6300
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!RemoveVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f59d0
[IAT:Addr] (explorer.exe @ clr.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ clr.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ MSVCR120_CLR0400.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ clrjit.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ clrjit.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ clrjit.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7bea9d0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beae50
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr(Microsoft)] (explorer.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (explorer.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ ieframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ stobject.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ InputSwitch.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ prnfldr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ DeviceSetupManagerAPI.dll) kernel32!PackageFamilyNameFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61bd0
[IAT:Addr] (explorer.exe @ DXP.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ shdocvw.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ Actioncenter.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msiltcfg.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msi.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpdshserviceobj.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ PortableDeviceApi.dll) kernel32!GetCurrentPackageFamilyName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5bef0
[IAT:Addr] (explorer.exe @ SettingMonitor.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ DropboxExt64.16.0.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ pnidui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ srchadmin.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ bthprops.cpl) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ SyncCenter.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (explorer.exe @ SyncCenter.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ imapi2.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ imapi2.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ davclnt.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ davhlpr.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ hgcpl.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ duser.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ FXSST.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ FXSST.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ FXSST.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ FXSST.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ FXSAPI.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ winspool.drv) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (explorer.exe @ winspool.drv) kernel32!GetCurrentPackageFamilyName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5bef0
[IAT:Addr] (explorer.exe @ GdiPlus.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ IconCodecService.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wscapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wscui.cpl) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ wscui.cpl) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ tishell64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ tishell64.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ tishell64.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ timounter64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ DirectShellExt.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ WorkfoldersShell.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ wpfgfx_v0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ PresentationNative_v0400.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ contextmenu64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ ATL90.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcp90.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msvcr90.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ shellExt.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ CLVDShellExt.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ syncui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ syncui.dll) user32!DefDlgProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615e90
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ 7-zip.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ FileSyncShell64.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ LoggingPlatform64.DLL) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ LoggingPlatform64.DLL) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcp120.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ msvcr120.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ acppage.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ acppage.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ dui70.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ tiptsf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ UIRibbon.dll) gdi32!ScriptBreak : C:\Windows\System32\gdi32full.dll @ 0x7ffae7f8d9e0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) gdi32!ScriptItemize : C:\Windows\System32\gdi32full.dll @ 0x7ffae7f9e8b0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b74d20
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b8e2e0
[IAT:Addr(Microsoft)] (explorer.exe @ UIRibbon.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (explorer.exe @ UIRibbon.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ UIRibbon.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (explorer.exe @ UIRibbon.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (explorer.exe @ daxexec.dll) kernel32!FormatApplicationUserModelId : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b642b0
[IAT:Addr(Microsoft)] (explorer.exe @ daxexec.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (explorer.exe @ NPSMDesktopProvider.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ zipfldr.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (explorer.exe @ wpdshext.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b8e2e0
[IAT:Addr(Microsoft)] (explorer.exe @ wpdshext.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b74d20
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!SetThreadpoolTimerEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfda0
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf800
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ wpdshext.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!EventActivityIdControl : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e1290
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ wpdshext.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ wpdshext.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ EhStorShell.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (explorer.exe @ EhStorAPI.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b61c50
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b5c880
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5180
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c4230
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c1900
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfeb0
[IAT:Addr] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7bea9d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beae50
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c0c90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bf8e0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b69010
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5c20e0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97820
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97360
[IAT:Addr] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97820
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d972a0
[IAT:Addr] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5f90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b5eb0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e3260
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b89de0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b94040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7beb8f0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d972a0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb585b20
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ explorerframe.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ explorerframe.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ explorerframe.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ msfeeds.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ msfeeds.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x7ffae7b6b4f0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1220
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5825c0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5430
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b00
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f5b40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!RegisterTraceGuidsW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582740
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cf9f0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!TraceMessage : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d06a0
[IAT:Addr] (iexplore.exe @ msfeeds.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1bd0
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97520
[IAT:Addr(Microsoft)] (iexplore.exe @ ntshrui.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ ntshrui.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ntshrui.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Addr(Microsoft)] (iexplore.exe @ ntlanman.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ davclnt.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr] (iexplore.exe @ davhlpr.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5b65c0
[IAT:Addr(Microsoft)] (iexplore.exe @ dui70.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ dui70.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ duser.dll) user32!DefWindowProcA : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dc0
[IAT:Addr] (iexplore.exe @ tiptsf.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoree.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a1a50
[IAT:Addr] (iexplore.exe @ mscoree.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5780
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoree.dll) user32!MessageBoxW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d978e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mscoreei.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ mscoreei.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ mscoreei.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!GetCurrentProcessorNumber : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615cc0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bfd90
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5bef30
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr(Microsoft)] (iexplore.exe @ clr.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!FlushProcessWriteBuffers : C:\Windows\System32\ntdll.dll @ 0x7ffaeb617c80
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbb70
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!AddVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6300
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!RemoveVectoredExceptionHandler : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5f59d0
[IAT:Addr] (iexplore.exe @ clr.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clr.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d1270
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr(Microsoft)] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d6c30
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb6199c0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7f70
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe70
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5dbe60
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5867f0
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e7c90
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ MSVCR120_CLR0400.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5cfa40
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7ffaeb582810
[IAT:Addr] (iexplore.exe @ clrjit.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d12b0
[IAT:Addr] (iexplore.exe @ clrjit.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ clrjit.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ clrjit.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5d7160
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a7930
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a5910
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ac200
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5ecda0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0bd0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5a0e40
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x7ffaeb5e6430
[IAT:Addr(Microsoft)] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!GetProcAddress : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d62ab0
[IAT:Addr] (iexplore.exe @ DropboxExt64.16.0.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7ffaeb586320
[IAT:Addr(Microsoft)] (iexplore.exe @ zipfldr.dll) user32!EnableWindow : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d740c0
[IAT:Addr] (iexplore.exe @ zipfldr.dll) user32!DefWindowProcW : C:\Windows\System32\ntdll.dll @ 0x7ffaeb615dd0
[IAT:Addr(Microsoft)] (iexplore.exe @ zipfldr.dll) user32!DialogBoxParamW : C:\Program Files\Internet Explorer\IEShims.dll @ 0x7ffac3d97440
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetTickCount : C:\Windows\System32\KERNELBASE.dll @ 0x76031940 (call dword [0x75a015dc])
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetNativeSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034cf0 (jmp dword [0x75a015f8])
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetSystemTimeAsFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7601c450 (jmp dword [0x75a0160c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateSemaphoreExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b070 (jmp dword [0x75a01520])
[IAT:Inl] (iexplore.exe) kernel32!SetLastError : C:\Windows\System32\ntdll.dll @ 0x777792b0 (jmp dword [0x75a019e0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetCommandLineW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e140 (jmp dword [0x75a011f8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseSemaphore : C:\Windows\System32\KERNELBASE.dll @ 0x760557c0 (jmp dword [0x75a01568])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringA : C:\Windows\System32\KERNELBASE.dll @ 0x760575e0 (jmp dword [0x75a00c90])
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObject : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae60 (jmp dword [0x75a01580])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseMutex : C:\Windows\System32\KERNELBASE.dll @ 0x76031b00 (jmp dword [0x75a01564])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetLastError : C:\Windows\System32\KERNELBASE.dll @ 0x76029f30 (jmp dword [0x75a00cd0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringW : C:\Windows\System32\KERNELBASE.dll @ 0x760574f0 (jmp dword [0x75a00c94])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObjectEx : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae80 (jmp dword [0x75a01584])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OpenSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b330 (jmp dword [0x75a01560])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CloseHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7602ad80 (jmp dword [0x75a00eac])
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateMutexExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b960 (jmp dword [0x75a01528])
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetProcessHeap : C:\Windows\System32\KERNELBASE.dll @ 0x76031c20 (jmp dword [0x75a00ec8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!IsDebuggerPresent : C:\Windows\System32\KERNELBASE.dll @ 0x7603dda0 (jmp dword [0x75a00c8c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!Sleep : C:\Windows\System32\KERNELBASE.dll @ 0x76032d70 (jmp dword [0x75a00a6c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetStartupInfoW : C:\Windows\System32\KERNELBASE.dll @ 0x7603a600 (jmp dword [0x75a012d8])
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x76017e20
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x760583d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SleepEx : C:\Windows\System32\KERNELBASE.dll @ 0x76032d90 (jmp dword [0x75a01578])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b560 (jmp dword [0x75a01534])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetThreadUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76048d70 (jmp dword [0x75a00fd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!WriteFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029360 (jmp dword [0x75a00e48])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFilePointer : C:\Windows\System32\KERNELBASE.dll @ 0x76033440 (jmp dword [0x75a00e30])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a5c0 (jmp dword [0x75a00dac])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesExW : C:\Windows\System32\KERNELBASE.dll @ 0x76039140 (jmp dword [0x75a00d88])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DeleteFileW : C:\Windows\System32\KERNELBASE.dll @ 0x76055330 (jmp dword [0x75a00d18])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSizeEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603c060 (jmp dword [0x75a00d98])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CompareFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x760390b0 (jmp dword [0x75a00dc0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetVolumePathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76050e20 (jmp dword [0x75a00df4])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!AreFileApisANSI : C:\Windows\System32\KERNELBASE.dll @ 0x7604c350 (jmp dword [0x75a009c4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFullPathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76039070 (jmp dword [0x75a00dd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c7a0 (jmp dword [0x75a00d8c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b4a0 (jmp dword [0x75a01524])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76033d80 (jmp dword [0x75a01570])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!ResetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76035530 (jmp dword [0x75a0156c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x76049b40 (jmp dword [0x75a00d9c])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DuplicateHandle : C:\Windows\System32\KERNELBASE.dll @ 0x760361d0 (jmp dword [0x75a00eb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x777b4020
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778ac30
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778acf0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!RaiseException : C:\Windows\System32\KERNELBASE.dll @ 0x7603a990 (jmp dword [0x75a00cbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7604b4e0 (jmp dword [0x75a00e2c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindClose : C:\Windows\System32\KERNELBASE.dll @ 0x760350a0 (jmp dword [0x75a00d24])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindNextFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a1f0 (jmp dword [0x75a00d58])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindFirstFileExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c090 (jmp dword [0x75a00dc4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSize : C:\Windows\System32\KERNELBASE.dll @ 0x76034c80 (jmp dword [0x75a00d94])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!ReadFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029d40 (jmp dword [0x75a00e0c])
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetCommandLineA : C:\Windows\System32\KERNELBASE.dll @ 0x7603e210 (jmp dword [0x75a011fc])
[IAT:Inl] (iexplore.exe @ eplgIE.dll) kernel32!RtlUnwind : C:\Windows\System32\ntdll.dll @ 0x777af000 (jmp dword [0x75a014b8])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetACP : C:\Windows\System32\KERNELBASE.dll @ 0x76039cc0 (jmp dword [0x75a01050])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetOEMCP : C:\Windows\System32\KERNELBASE.dll @ 0x76058bc0 (jmp dword [0x75a01074])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!TlsAlloc : C:\Windows\System32\KERNELBASE.dll @ 0x760397e0 (jmp dword [0x75a01278])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetFileType : C:\Windows\System32\KERNELBASE.dll @ 0x76036110 (jmp dword [0x75a00da0])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetEnvironmentStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76033560 (jmp dword [0x75a01214])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleCP : C:\Windows\System32\KERNELBASE.dll @ 0x760936e0 (jmp dword [0x75a00bac])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleMode : C:\Windows\System32\KERNELBASE.dll @ 0x7601fcf0 (jmp dword [0x75a00ba4])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!WriteConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094410 (jmp dword [0x75a00b78])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FlushFileBuffers : C:\Windows\System32\KERNELBASE.dll @ 0x76057fb0 (jmp dword [0x75a00d64])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetObjectW : C:\Windows\System32\gdi32full.dll @ 0x75ae2540 (jmp dword [0x74947018])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b05e80 (jmp dword [0x74947050])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetBitmapBitsSize : C:\Windows\System32\gdi32full.dll @ 0x75ae29c0 (jmp dword [0x74947628])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75ae4ee0 (jmp dword [0x74947100])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiValidateHandle : C:\Windows\System32\gdi32full.dll @ 0x75ae2490 (jmp dword [0x749476c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetMapMode : C:\Windows\System32\gdi32full.dll @ 0x75b072a0 (jmp dword [0x749470fc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetHFONT : C:\Windows\System32\gdi32full.dll @ 0x75b12980 (jmp dword [0x74947758])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b05f30 (jmp dword [0x749470a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDCOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b13c00 (jmp dword [0x7494702c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiFixUpHandle : C:\Windows\System32\gdi32full.dll @ 0x75b0cac0 (jmp dword [0x7494761c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiPrinterThunk : C:\Windows\System32\gdi32full.dll @ 0x75b4c7c0 (jmp dword [0x74947690])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiLoadType1Fonts : C:\Windows\System32\gdi32full.dll @ 0x75b3bb90 (jmp dword [0x74947674])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiAddFontResourceW : C:\Windows\System32\gdi32full.dll @ 0x75b3ba60 (jmp dword [0x7494757c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiProcessSetup : C:\Windows\System32\gdi32full.dll @ 0x75ae4090 (jmp dword [0x74947694])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiDllInitialize : C:\Windows\System32\gdi32full.dll @ 0x75ae3ea0 (jmp dword [0x749442d8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnableEUDC : C:\Windows\System32\gdi32full.dll @ 0x75b1c570 (jmp dword [0x74947444])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertBitmapV5 : C:\Windows\System32\gdi32full.dll @ 0x75b3e180 (jmp dword [0x7494759c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertToDevmodeW : C:\Windows\System32\gdi32full.dll @ 0x75b39e20 (jmp dword [0x749475bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!MirrorRgn : C:\Windows\System32\gdi32full.dll @ 0x75b3a3b0 (jmp dword [0x749477e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b174c0 (jmp dword [0x749476dc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b06e80 (jmp dword [0x749470a4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!ExcludeClipRect : C:\Windows\System32\gdi32full.dll @ 0x75b1abd0 (jmp dword [0x74947008])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CreateEllipticRgn : C:\Windows\System32\gdi32full.dll @ 0x75b39c40 (jmp dword [0x749472f4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!PolyPatBlt : C:\Windows\System32\gdi32full.dll @ 0x75b10850 (jmp dword [0x74947be4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetTextCharacterExtra : C:\Windows\System32\gdi32full.dll @ 0x75b07a40 (jmp dword [0x749471bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayoutWidth : C:\Windows\System32\gdi32full.dll @ 0x75b18d20 (jmp dword [0x74947c70])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertAndCheckDC : C:\Windows\System32\gdi32full.dll @ 0x75b16730 (jmp dword [0x74947594])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b16910 (jmp dword [0x74947c4c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyEnhMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b4dd60 (jmp dword [0x749472c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b44a70 (jmp dword [0x749472d0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharsetInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1b1d0 (jmp dword [0x749477ac])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!QueryFontAssocStatus : C:\Windows\System32\gdi32full.dll @ 0x75b196e0 (jmp dword [0x74947bfc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharWidthInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1ca20 (jmp dword [0x74947704])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceW : C:\Windows\System32\gdi32full.dll @ 0x75ae8930 (jmp dword [0x74947174])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsW : C:\Windows\System32\gdi32full.dll @ 0x75b15a30 (jmp dword [0x74947134])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsA : C:\Windows\System32\gdi32full.dll @ 0x75b36d40 (jmp dword [0x749476e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b076a0 (jmp dword [0x749470e0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceAliasW : C:\Windows\System32\gdi32full.dll @ 0x75ae8030 (jmp dword [0x749477b8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnumFontsW : C:\Windows\System32\gdi32full.dll @ 0x75b10e80 (jmp dword [0x749471a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b51010 (jmp dword [0x749475c0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b51030 (jmp dword [0x749475c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b50f20 (jmp dword [0x749475a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b50f90 (jmp dword [0x749475b0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75afd6e0 (jmp dword [0x74947178])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!TextOutW : C:\Windows\System32\gdi32full.dll @ 0x75b47680 (jmp dword [0x74947184])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetWindowExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecf90 (jmp dword [0x749470f0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetViewportExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecec0 (jmp dword [0x749477c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBkMode : C:\Windows\System32\gdi32full.dll @ 0x75b043f0 (jmp dword [0x7494706c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCharDimensions : C:\Windows\System32\gdi32full.dll @ 0x75b13cb0 (jmp dword [0x7494762c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharset : C:\Windows\System32\gdi32full.dll @ 0x75b17c90 (jmp dword [0x749471a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCodePage : C:\Windows\System32\gdi32full.dll @ 0x75b11760 (jmp dword [0x74947630])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextExtentPointW : C:\Windows\System32\gdi32full.dll @ 0x75afaf60 (jmp dword [0x74947194])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!OffsetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b14060 (jmp dword [0x749470e8])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!InvalidateRect : C:\Windows\System32\win32u.dll @ 0x753124c0 (jmp dword [0x74bffb9c])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetKeyboardLayoutList : C:\Windows\System32\win32u.dll @ 0x75312a00 (jmp dword [0x74bffc8c])
[IAT:Addr(Microsoft)] (iexplore.exe @ gdi32full.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetDC : C:\Windows\System32\win32u.dll @ 0x75312520 (jmp dword [0x74bffcc4])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetForegroundWindow : C:\Windows\System32\win32u.dll @ 0x75312840 (jmp dword [0x74bffcac])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75312bf0 (jmp dword [0x74bffc88])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!DestroyWindow : C:\Windows\System32\win32u.dll @ 0x75312e40 (jmp dword [0x74bffd50])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!ShowWindow : C:\Windows\System32\win32u.dll @ 0x753129f0 (jmp dword [0x74bffa18])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!EndPaint : C:\Windows\System32\win32u.dll @ 0x75312610 (jmp dword [0x74bffd00])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!BeginPaint : C:\Windows\System32\win32u.dll @ 0x753125f0 (jmp dword [0x74bffdb8])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetWindowPos : C:\Windows\System32\win32u.dll @ 0x753126c0 (jmp dword [0x74bffa2c])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetCapture : C:\Windows\System32\win32u.dll @ 0x75312910 (jmp dword [0x74bffab8])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetFocus : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcessMitigationPolicy : C:\Windows\System32\KERNELBASE.dll @ 0x7603af60
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetThreadLocale : C:\Windows\System32\KERNELBASE.dll @ 0x7603b480 (jmp dword [0x75a01060])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetSystemDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c630 (jmp dword [0x75a01064])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl] (iexplore.exe @ imm32.dll) kernel32!RtlCaptureContext : C:\Windows\System32\ntdll.dll @ 0x777d2e00 (jmp dword [0x75a014c4])
[IAT:Inl] (iexplore.exe @ imm32.dll) gdi32!GetTextExtentPoint32W : C:\Windows\System32\gdi32full.dll @ 0x75afe460 (jmp dword [0x74947198])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CopyFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7603f280 (jmp dword [0x75a00ea4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempPathW : C:\Windows\System32\KERNELBASE.dll @ 0x7603d040 (jmp dword [0x75a00de4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempFileNameW : C:\Windows\System32\KERNELBASE.dll @ 0x7604f170 (jmp dword [0x75a00ddc])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bb760
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bba70
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b3d0 (jmp dword [0x75a0155c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034d50 (jmp dword [0x75a01600])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c490 (jmp dword [0x75a01030])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x76035480 (jmp dword [0x75a01604])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionAndSpinCount : C:\Windows\System32\KERNELBASE.dll @ 0x76034c60 (jmp dword [0x75a0154c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604fe20 (jmp dword [0x75a00e38])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetFinalPathNameByHandleW : C:\Windows\System32\KERNELBASE.dll @ 0x76046b60 (jmp dword [0x75a00dc8])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLocalTime : C:\Windows\System32\KERNELBASE.dll @ 0x760344b0 (jmp dword [0x75a015f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x760345d0 (jmp dword [0x75a01668])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToLocalFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604a210 (jmp dword [0x75a00d20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc440 (jmp dword [0x75a016cc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateMutexA : C:\Windows\System32\KERNELBASE.dll @ 0x76051fb0 (jmp dword [0x75a01530])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjects : C:\Windows\System32\KERNELBASE.dll @ 0x76031c30 (jmp dword [0x75a015b8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x76057af0 (jmp dword [0x75a00e28])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b670 (jmp dword [0x75a01544])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b040 (jmp dword [0x75a015b4])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034ec0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CancelWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045b70 (jmp dword [0x75a01540])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76050660 (jmp dword [0x75a01034])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76047db0 (jmp dword [0x75a01068])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjectsEx : C:\Windows\System32\KERNELBASE.dll @ 0x76031c60 (jmp dword [0x75a0157c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045120 (jmp dword [0x75a01574])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c070 (jmp dword [0x75a00d44])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDriveTypeW : C:\Windows\System32\KERNELBASE.dll @ 0x76035950 (jmp dword [0x75a00d7c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventA : C:\Windows\System32\KERNELBASE.dll @ 0x7602b5d0 (jmp dword [0x75a0153c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateFile2 : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6a0 (jmp dword [0x75a00db4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76057ee0 (jmp dword [0x75a016d8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LocalFileTimeToFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604edf0 (jmp dword [0x75a00dfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetEndOfFile : C:\Windows\System32\KERNELBASE.dll @ 0x7603d520 (jmp dword [0x75a00e20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDiskFreeSpaceExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603bbe0 (jmp dword [0x75a00d70])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!UnlockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6d0 (jmp dword [0x75a00e40])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604cb60 (jmp dword [0x75a00e00])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLogicalDriveStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76059010 (jmp dword [0x75a00dd4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!QueryDosDeviceW : C:\Windows\System32\KERNELBASE.dll @ 0x76056b40 (jmp dword [0x75a00e08])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetVersion : C:\Windows\System32\KERNELBASE.dll @ 0x76057ca0 (jmp dword [0x75a01610])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x7603e150 (jmp dword [0x75a00a3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034fa0 (jmp dword [0x75a01550])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!ReleaseActCtx : C:\Windows\System32\KERNELBASE.dll @ 0x76057c50 (jmp dword [0x75a014f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76034390 (jmp dword [0x75a00a40])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b720 (jmp dword [0x75a01558])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!RemoveDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e600 (jmp dword [0x75a00e1c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76039bb0 (jmp dword [0x75a00db8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b43e80 (jmp dword [0x7494704c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiTransparentBlt : C:\Windows\System32\gdi32full.dll @ 0x75b182f0 (jmp dword [0x74947108])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiGradientFill : C:\Windows\System32\gdi32full.dll @ 0x75b134a0 (jmp dword [0x7494710c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiAlphaBlend : C:\Windows\System32\gdi32full.dll @ 0x75b107c0 (jmp dword [0x749470cc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b0cb10 (jmp dword [0x74947104])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateHalftonePalette : C:\Windows\System32\gdi32full.dll @ 0x75b1b1b0 (jmp dword [0x74947304])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!PtInRegion : C:\Windows\System32\gdi32full.dll @ 0x75b3a610 (jmp dword [0x7494436c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateFontW : C:\Windows\System32\gdi32full.dll @ 0x75b16130 (jmp dword [0x749471b8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiFlush : C:\Windows\System32\gdi32full.dll @ 0x75b13800 (jmp dword [0x74947060])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCPenColor : C:\Windows\System32\gdi32full.dll @ 0x75b441a0 (jmp dword [0x74947c5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b44000 (jmp dword [0x7494701c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetTextExtentExPointW : C:\Windows\System32\gdi32full.dll @ 0x75b17ea0 (jmp dword [0x74947168])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateDIBPatternBrushPt : C:\Windows\System32\gdi32full.dll @ 0x75b39c00 (jmp dword [0x74947124])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!MoveWindow : C:\Windows\System32\win32u.dll @ 0x75312a50 (jmp dword [0x74bffb58])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WaitMessage : C:\Windows\System32\win32u.dll @ 0x75312540 (jmp dword [0x74bff9b4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackPopupMenuEx : C:\Windows\System32\win32u.dll @ 0x753169b0 (jmp dword [0x74bff9f4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DeleteMenu : C:\Windows\System32\win32u.dll @ 0x75313030 (jmp dword [0x74bffd5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!CopyAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75312740 (jmp dword [0x74bffd70])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!KillTimer : C:\Windows\System32\win32u.dll @ 0x75312630 (jmp dword [0x74bffb78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetDoubleClickTime : C:\Windows\System32\win32u.dll @ 0x75312fd0 (jmp dword [0x74bffcb0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WindowFromPoint : C:\Windows\System32\win32u.dll @ 0x753125c0 (jmp dword [0x74bff9ac])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageTime : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!AttachThreadInput : C:\Windows\System32\win32u.dll @ 0x75313320 (jmp dword [0x74bffdbc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetSystemMenu : C:\Windows\System32\win32u.dll @ 0x75312a80 (jmp dword [0x74bffc1c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!FlashWindowEx : C:\Windows\System32\win32u.dll @ 0x75315bd0 (jmp dword [0x74bffcf4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowDC : C:\Windows\System32\win32u.dll @ 0x75312ab0 (jmp dword [0x74bffbf8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackMouseEvent : C:\Windows\System32\win32u.dll @ 0x75313210 (jmp dword [0x74bff9f8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SendInput : C:\Windows\System32\win32u.dll @ 0x75312c90 (jmp dword [0x74bffad8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetGUIThreadInfo : C:\Windows\System32\win32u.dll @ 0x75313450 (jmp dword [0x74bffca8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x753131b0 (jmp dword [0x74bffbe8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetTitleBarInfo : C:\Windows\System32\win32u.dll @ 0x75312d60 (jmp dword [0x74bffc14])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75313350 (jmp dword [0x74bffa78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!PrintWindow : C:\Windows\System32\win32u.dll @ 0x753163a0 (jmp dword [0x74bffb38])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetComboBoxInfo : C:\Windows\System32\win32u.dll @ 0x75315c60 (jmp dword [0x74bffcd0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RedrawWindow : C:\Windows\System32\win32u.dll @ 0x753125b0 (jmp dword [0x74bffb24])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageExtraInfo : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ShowScrollBar : C:\Windows\System32\win32u.dll @ 0x75312850 (jmp dword [0x74bffa20])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x75313280 (jmp dword [0x74bffa30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75313260 (jmp dword [0x74bffac8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ChangeWindowMessageFilterEx : C:\Windows\System32\win32u.dll @ 0x753158f0 (jmp dword [0x74bffda0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EnumDisplayMonitors : C:\Windows\System32\win32u.dll @ 0x75312920 (jmp dword [0x74bffcfc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetClipCursor : C:\Windows\System32\win32u.dll @ 0x75315c30 (jmp dword [0x74bffcd8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ValidateRect : C:\Windows\System32\win32u.dll @ 0x75313140 (jmp dword [0x74bff9c0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCaretBlinkTime : C:\Windows\System32\win32u.dll @ 0x753133a0 (jmp dword [0x74bffce0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EndMenu : C:\Windows\System32\win32u.dll @ 0x75315bb0 (jmp dword [0x74bffd04])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75316760 (jmp dword [0x74bffa74])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetRawInputData : C:\Windows\System32\win32u.dll @ 0x75315f30 (jmp dword [0x74bffc30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RegisterRawInputDevices : C:\Windows\System32\win32u.dll @ 0x753164c0 (jmp dword [0x74bffb0c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCursor : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMenuItemRect : C:\Windows\System32\win32u.dll @ 0x75315e00 (jmp dword [0x74bffc74])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RemoveMenu : C:\Windows\System32\win32u.dll @ 0x75313400 (jmp dword [0x74bffae8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DestroyMenu : C:\Windows\System32\win32u.dll @ 0x75313230 (jmp dword [0x74bffd54])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetFocus : C:\Windows\System32\win32u.dll @ 0x75312990 (jmp dword [0x74bffa8c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetMenuDefaultItem : C:\Windows\System32\win32u.dll @ 0x75313480 (jmp dword [0x74bffa68])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetAncestor : C:\Windows\System32\win32u.dll @ 0x75312f90 (jmp dword [0x74bffcec])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesA : C:\Windows\System32\gdi32full.dll @ 0x75b37280 (jmp dword [0x7494774c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesW : C:\Windows\System32\gdi32full.dll @ 0x75b18460 (jmp dword [0x7494714c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetTextExtentExPointI : C:\Windows\System32\gdi32full.dll @ 0x75b37890 (jmp dword [0x7494719c])
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230830
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!GetFullPathNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bbe80 (jmp dword [0x75a00dcc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!CreateFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d600 (jmp dword [0x75a00db0])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!OffsetViewportOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b12db0 (jmp dword [0x74947088])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b071e0 (jmp dword [0x749470ec])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!EnumFontFamiliesExW : C:\Windows\System32\gdi32full.dll @ 0x75b10f90 (jmp dword [0x74947188])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayEnhMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b04c10 (jmp dword [0x74947bd4])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetWinMetaFileBits : C:\Windows\System32\gdi32full.dll @ 0x75b4e4b0 (jmp dword [0x74947c9c])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b0a230 (jmp dword [0x74947bd8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b13b90 (jmp dword [0x74947754])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b39fa0 (jmp dword [0x749476d8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b3a0a0 (jmp dword [0x74947c44])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!CheckProcessForClipboardAccess : C:\Windows\System32\win32u.dll @ 0x75315910 (jmp dword [0x74bffd9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!SetWindowWord : C:\Windows\System32\win32u.dll @ 0x753132e0 (jmp dword [0x74bffa24])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetAutoRotationState : C:\Windows\System32\win32u.dll @ 0x75315c00 (jmp dword [0x74bffce8])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetCurrentInputMessageSource : C:\Windows\System32\win32u.dll @ 0x75315c70 (jmp dword [0x74bffccc])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!ShutdownBlockReasonDestroy : C:\Windows\System32\win32u.dll @ 0x75316940 (jmp dword [0x74bffa10])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!UnhookWinEvent : C:\Windows\System32\win32u.dll @ 0x753134b0 (jmp dword [0x74bff9ec])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!LockWindowUpdate : C:\Windows\System32\win32u.dll @ 0x753134c0 (jmp dword [0x74bffb6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetShellWindowEx : C:\Windows\System32\win32u.dll @ 0x75316820 (jmp dword [0x74bffa50])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CreateAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75313370 (jmp dword [0x74bffd6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetCoalescableTimer : C:\Windows\System32\win32u.dll @ 0x75312600 (jmp dword [0x74bffaac])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetPointerDevices : C:\Windows\System32\win32u.dll @ 0x75315e80 (jmp dword [0x74bffc50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CloseDesktop : C:\Windows\System32\win32u.dll @ 0x75312ed0 (jmp dword [0x74bffd84])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!OpenInputDesktop : C:\Windows\System32\win32u.dll @ 0x75316350 (jmp dword [0x74bffb50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetWindowBand : C:\Windows\System32\win32u.dll @ 0x75315fd0 (jmp dword [0x74bffc04])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetGestureConfig : C:\Windows\System32\win32u.dll @ 0x753166f0 (jmp dword [0x74bffa88])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetUserObjectInformationW : C:\Windows\System32\win32u.dll @ 0x75312b30 (jmp dword [0x74bffc08])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetProcessWindowStation : C:\Windows\System32\win32u.dll @ 0x753126a0 (jmp dword [0x74bffc38])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetThreadDesktop : C:\Windows\System32\win32u.dll @ 0x75312ca0 (jmp dword [0x74bffc18])
[IAT:Inl] (iexplore.exe @ shell32.dll) gdi32!PlgBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46ae0 (jmp dword [0x749470e4])
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!MaskBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46710 (jmp dword [0x749477e0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75b47870 (jmp dword [0x749470dc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetPixelV : C:\Windows\System32\gdi32full.dll @ 0x75b47210 (jmp dword [0x74947c7c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetCharWidthW : C:\Windows\System32\gdi32full.dll @ 0x75b125d0 (jmp dword [0x7494713c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetNearestColor : C:\Windows\System32\gdi32full.dll @ 0x75b16940 (jmp dword [0x7494777c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetDCEx : C:\Windows\System32\win32u.dll @ 0x75312d90 (jmp dword [0x74bffcc0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetScrollBarInfo : C:\Windows\System32\win32u.dll @ 0x75312da0 (jmp dword [0x74bffc20])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!ShowWindowAsync : C:\Windows\System32\win32u.dll @ 0x75313610 (jmp dword [0x74bffa14])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!IsTopLevelWindow : C:\Windows\System32\win32u.dll @ 0x75316210 (jmp dword [0x74bffb84])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetCaretPos : C:\Windows\System32\win32u.dll @ 0x75315c20 (jmp dword [0x74bffcdc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!InvalidateRgn : C:\Windows\System32\win32u.dll @ 0x753130f0 (jmp dword [0x74bffb98])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!RegisterTouchHitTestingWindow : C:\Windows\System32\win32u.dll @ 0x75316510 (jmp dword [0x74bffaf8])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!DragDetect : C:\Windows\System32\win32u.dll @ 0x75315aa0 (jmp dword [0x74bffd40])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!BlockInput : C:\Windows\System32\win32u.dll @ 0x75315870 (jmp dword [0x74bffdb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!GetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7603b170 (jmp dword [0x75a00d90])
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x777b19d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603e960
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603eed0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comdlg32.dll) user32!ClipCursor : C:\Windows\System32\win32u.dll @ 0x75315960 (jmp dword [0x74bffd88])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!GetCharWidth32W : C:\Windows\System32\gdi32full.dll @ 0x75b36e00 (jmp dword [0x749476f4])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!CreateDiscardableBitmap : C:\Windows\System32\gdi32full.dll @ 0x75b39c30 (jmp dword [0x749472f0])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GetRandomRgn : C:\Windows\System32\gdi32full.dll @ 0x75b15c40 (jmp dword [0x74944300])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GdiDrawStream : C:\Windows\System32\gdi32full.dll @ 0x75b13580 (jmp dword [0x749475d4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!SetBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a890 (jmp dword [0x74947c40])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ExtCreatePen : C:\Windows\System32\gdi32full.dll @ 0x75b18db0 (jmp dword [0x74947530])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!AbortPath : C:\Windows\System32\gdi32full.dll @ 0x75b478f0 (jmp dword [0x7494725c])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!StrokeAndFillPath : C:\Windows\System32\gdi32full.dll @ 0x75b47a70 (jmp dword [0x74947cb4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!CreateSessionMappedDIBSection : C:\Windows\System32\gdi32full.dll @ 0x75b3a710 (jmp dword [0x74947318])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ClearBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a6d0 (jmp dword [0x749472ac])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!CalcMenuBar : C:\Windows\System32\win32u.dll @ 0x75312de0 (jmp dword [0x74bffdac])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!PaintMenuBar : C:\Windows\System32\win32u.dll @ 0x75313340 (jmp dword [0x74bffb48])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!GetMenuBarInfo : C:\Windows\System32\win32u.dll @ 0x75313080 (jmp dword [0x74bffc78])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitOnceInitialize : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x77788520
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!DeleteFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c5f0 (jmp dword [0x75a00cfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SwitchToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x76049e70 (jmp dword [0x75a00cf8])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604a2f0 (jmp dword [0x75a00d04])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertThreadToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c4e0 (jmp dword [0x75a00d0c])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertFiberToThread : C:\Windows\System32\KERNELBASE.dll @ 0x7604de70 (jmp dword [0x75a00d10])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetDiskFreeSpaceW : C:\Windows\System32\KERNELBASE.dll @ 0x760bc140 (jmp dword [0x75a00d74])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl] (iexplore.exe @ mshtml.dll) kernel32!WTSGetActiveConsoleSessionId : C:\Windows\System32\ntdll.dll @ 0x7779fce0 (jmp dword [0x75a019b0])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!CreateHatchBrush : C:\Windows\System32\gdi32full.dll @ 0x75b39d10 (jmp dword [0x74947308])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetFontUnicodeRanges : C:\Windows\System32\gdi32full.dll @ 0x75b1b1c0 (jmp dword [0x74947748])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetGlyphOutlineW : C:\Windows\System32\gdi32full.dll @ 0x75b13080 (jmp dword [0x74947150])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetOutlineTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75aecc70 (jmp dword [0x74947158])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!AddFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3af20 (jmp dword [0x749471b4])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!RemoveFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3c040 (jmp dword [0x74947190])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!EnumObjects : C:\Windows\System32\gdi32full.dll @ 0x75b39d30 (jmp dword [0x74947058])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75315dd0 (jmp dword [0x74bffc84])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetCursorInfo : C:\Windows\System32\win32u.dll @ 0x75315c90 (jmp dword [0x74bffcc8])
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!ChildWindowFromPointEx : C:\Windows\System32\win32u.dll @ 0x75315940 (jmp dword [0x74bffd90])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x777a7480
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetWindowCompositionAttribute : C:\Windows\System32\win32u.dll @ 0x75315fe0 (jmp dword [0x74bffc00])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!UpdateDefaultDesktopThumbnail : C:\Windows\System32\win32u.dll @ 0x75316a40 (jmp dword [0x74bff9d4])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!SetWindowCompositionTransition : C:\Windows\System32\win32u.dll @ 0x753168b0 (jmp dword [0x74bffa3c])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetGuiResources : C:\Windows\System32\win32u.dll @ 0x75315d30 (jmp dword [0x74bffca0])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ msctf.dll) user32!GetInputLocaleInfo : C:\Windows\System32\win32u.dll @ 0x75315d70 (jmp dword [0x74bffc9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!ModifyWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b05a80 (jmp dword [0x749477e8])
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!GetWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b174f0 (jmp dword [0x74947084])
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7777dea0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x777b6750
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x777b6bb0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x777b6be0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x777b6790
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x777bd520
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!SetFilePointerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603a010 (jmp dword [0x75a00e34])
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!DebugBreak : C:\Windows\System32\KERNELBASE.dll @ 0x760b48d0 (jmp dword [0x75a00c88])
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetFileAttributesA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d930 (jmp dword [0x75a00d80])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateDirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x76039b70 (jmp dword [0x75a00dbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!FindFirstFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d1f0 (jmp dword [0x75a00d34])
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x77822cc0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7779e380
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7777def0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x777a7450
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!FatalAppExitA : C:\Windows\System32\KERNELBASE.dll @ 0x760b8c30 (jmp dword [0x75a00a88])
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!SetConsoleCtrlHandler : C:\Windows\System32\KERNELBASE.dll @ 0x7603e350 (jmp dword [0x75a00b84])
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230a10
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!RegisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316480 (jmp dword [0x74bffb18])
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!UnregisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316a10 (jmp dword [0x74bff9e0])
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!MenuItemFromPoint : C:\Windows\System32\win32u.dll @ 0x75316300 (jmp dword [0x74bffb5c])
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!SetConsoleTextAttribute : C:\Windows\System32\KERNELBASE.dll @ 0x76093c80 (jmp dword [0x75a00bf4])
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetConsoleScreenBufferInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76093770 (jmp dword [0x75a00c20])
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EncodeSystemPointer : C:\Windows\System32\ntdll.dll @ 0x777753d0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempFileNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc460 (jmp dword [0x75a00e54])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempPathA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc590 (jmp dword [0x75a00e60])
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!DeleteFileA : C:\Windows\System32\KERNELBASE.dll @ 0x76054340 (jmp dword [0x75a00d3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7602c870
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7603e110
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Inl] (iexplore.exe @ t2embed.dll) gdi32!CreateScalableFontResourceA : C:\Windows\System32\gdi32full.dll @ 0x75b3b2d0 (jmp dword [0x74947310])
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!ReadConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094300 (jmp dword [0x75a00b88])
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr] (iexplore.exe @ atiumdva.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atiumdva.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetTickCount : C:\Windows\System32\KERNELBASE.dll @ 0x76031940 (call dword [0x75a015dc])
[IAT:Addr] (iexplore.exe) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetNativeSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034cf0 (jmp dword [0x75a015f8])
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetSystemTimeAsFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7601c450 (jmp dword [0x75a0160c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateSemaphoreExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b070 (jmp dword [0x75a01520])
[IAT:Inl] (iexplore.exe) kernel32!SetLastError : C:\Windows\System32\ntdll.dll @ 0x777792b0 (jmp dword [0x75a019e0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetCommandLineW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e140 (jmp dword [0x75a011f8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseSemaphore : C:\Windows\System32\KERNELBASE.dll @ 0x760557c0 (jmp dword [0x75a01568])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringA : C:\Windows\System32\KERNELBASE.dll @ 0x760575e0 (jmp dword [0x75a00c90])
[IAT:Addr] (iexplore.exe) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObject : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae60 (jmp dword [0x75a01580])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!ReleaseMutex : C:\Windows\System32\KERNELBASE.dll @ 0x76031b00 (jmp dword [0x75a01564])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetLastError : C:\Windows\System32\KERNELBASE.dll @ 0x76029f30 (jmp dword [0x75a00cd0])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OutputDebugStringW : C:\Windows\System32\KERNELBASE.dll @ 0x760574f0 (jmp dword [0x75a00c94])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!WaitForSingleObjectEx : C:\Windows\System32\KERNELBASE.dll @ 0x7602ae80 (jmp dword [0x75a01584])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!OpenSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b330 (jmp dword [0x75a01560])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CloseHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7602ad80 (jmp dword [0x75a00eac])
[IAT:Addr] (iexplore.exe) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!CreateMutexExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b960 (jmp dword [0x75a01528])
[IAT:Addr] (iexplore.exe) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetProcessHeap : C:\Windows\System32\KERNELBASE.dll @ 0x76031c20 (jmp dword [0x75a00ec8])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!IsDebuggerPresent : C:\Windows\System32\KERNELBASE.dll @ 0x7603dda0 (jmp dword [0x75a00c8c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!Sleep : C:\Windows\System32\KERNELBASE.dll @ 0x76032d70 (jmp dword [0x75a00a6c])
[IAT:Inl(Microsoft)] (iexplore.exe) kernel32!GetStartupInfoW : C:\Windows\System32\KERNELBASE.dll @ 0x7603a600 (jmp dword [0x75a012d8])
[IAT:Addr] (iexplore.exe) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!PackageIdFromFullName : C:\Windows\System32\KERNELBASE.dll @ 0x76017e20
[IAT:Addr(Microsoft)] (iexplore.exe @ apphelp.dll) kernel32!GetPackageFullName : C:\Windows\System32\KERNELBASE.dll @ 0x760583d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SleepEx : C:\Windows\System32\KERNELBASE.dll @ 0x76032d90 (jmp dword [0x75a01578])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b560 (jmp dword [0x75a01534])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetThreadUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76048d70 (jmp dword [0x75a00fd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!WriteFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029360 (jmp dword [0x75a00e48])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFilePointer : C:\Windows\System32\KERNELBASE.dll @ 0x76033440 (jmp dword [0x75a00e30])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a5c0 (jmp dword [0x75a00dac])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesExW : C:\Windows\System32\KERNELBASE.dll @ 0x76039140 (jmp dword [0x75a00d88])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DeleteFileW : C:\Windows\System32\KERNELBASE.dll @ 0x76055330 (jmp dword [0x75a00d18])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSizeEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603c060 (jmp dword [0x75a00d98])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CompareFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x760390b0 (jmp dword [0x75a00dc0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetVolumePathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76050e20 (jmp dword [0x75a00df4])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!AreFileApisANSI : C:\Windows\System32\KERNELBASE.dll @ 0x7604c350 (jmp dword [0x75a009c4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFullPathNameW : C:\Windows\System32\KERNELBASE.dll @ 0x76039070 (jmp dword [0x75a00dd0])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c7a0 (jmp dword [0x75a00d8c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!CreateMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b4a0 (jmp dword [0x75a01524])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76033d80 (jmp dword [0x75a01570])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!ResetEvent : C:\Windows\System32\KERNELBASE.dll @ 0x76035530 (jmp dword [0x75a0156c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x76049b40 (jmp dword [0x75a00d9c])
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!DuplicateHandle : C:\Windows\System32\KERNELBASE.dll @ 0x760361d0 (jmp dword [0x75a00eb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CloseThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x777b4020
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!CancelThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778ac30
[IAT:Addr] (iexplore.exe @ advapi32.dll) kernel32!StartThreadpoolIo : C:\Windows\System32\ntdll.dll @ 0x7778acf0
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!RaiseException : C:\Windows\System32\KERNELBASE.dll @ 0x7603a990 (jmp dword [0x75a00cbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!SetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7604b4e0 (jmp dword [0x75a00e2c])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindClose : C:\Windows\System32\KERNELBASE.dll @ 0x760350a0 (jmp dword [0x75a00d24])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindNextFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602a1f0 (jmp dword [0x75a00d58])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!FindFirstFileExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c090 (jmp dword [0x75a00dc4])
[IAT:Inl(Microsoft)] (iexplore.exe @ advapi32.dll) kernel32!GetFileSize : C:\Windows\System32\KERNELBASE.dll @ 0x76034c80 (jmp dword [0x75a00d94])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!ReadFile : C:\Windows\System32\KERNELBASE.dll @ 0x76029d40 (jmp dword [0x75a00e0c])
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Addr(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetCommandLineA : C:\Windows\System32\KERNELBASE.dll @ 0x7603e210 (jmp dword [0x75a011fc])
[IAT:Inl] (iexplore.exe @ eplgIE.dll) kernel32!RtlUnwind : C:\Windows\System32\ntdll.dll @ 0x777af000 (jmp dword [0x75a014b8])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetACP : C:\Windows\System32\KERNELBASE.dll @ 0x76039cc0 (jmp dword [0x75a01050])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetOEMCP : C:\Windows\System32\KERNELBASE.dll @ 0x76058bc0 (jmp dword [0x75a01074])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!TlsAlloc : C:\Windows\System32\KERNELBASE.dll @ 0x760397e0 (jmp dword [0x75a01278])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetFileType : C:\Windows\System32\KERNELBASE.dll @ 0x76036110 (jmp dword [0x75a00da0])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetEnvironmentStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76033560 (jmp dword [0x75a01214])
[IAT:Addr] (iexplore.exe @ eplgIE.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleCP : C:\Windows\System32\KERNELBASE.dll @ 0x760936e0 (jmp dword [0x75a00bac])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!GetConsoleMode : C:\Windows\System32\KERNELBASE.dll @ 0x7601fcf0 (jmp dword [0x75a00ba4])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!WriteConsoleW : C:\Windows\System32\KERNELBASE.dll @ 0x76094410 (jmp dword [0x75a00b78])
[IAT:Inl(Microsoft)] (iexplore.exe @ eplgIE.dll) kernel32!FlushFileBuffers : C:\Windows\System32\KERNELBASE.dll @ 0x76057fb0 (jmp dword [0x75a00d64])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetObjectW : C:\Windows\System32\gdi32full.dll @ 0x75ae2540 (jmp dword [0x74947018])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b05e80 (jmp dword [0x74947050])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetBitmapBitsSize : C:\Windows\System32\gdi32full.dll @ 0x75ae29c0 (jmp dword [0x74947628])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75ae4ee0 (jmp dword [0x74947100])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiValidateHandle : C:\Windows\System32\gdi32full.dll @ 0x75ae2490 (jmp dword [0x749476c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetMapMode : C:\Windows\System32\gdi32full.dll @ 0x75b072a0 (jmp dword [0x749470fc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetHFONT : C:\Windows\System32\gdi32full.dll @ 0x75b12980 (jmp dword [0x74947758])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b05f30 (jmp dword [0x749470a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetDCOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b13c00 (jmp dword [0x7494702c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiFixUpHandle : C:\Windows\System32\gdi32full.dll @ 0x75b0cac0 (jmp dword [0x7494761c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiPrinterThunk : C:\Windows\System32\gdi32full.dll @ 0x75b4c7c0 (jmp dword [0x74947690])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiLoadType1Fonts : C:\Windows\System32\gdi32full.dll @ 0x75b3bb90 (jmp dword [0x74947674])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiAddFontResourceW : C:\Windows\System32\gdi32full.dll @ 0x75b3ba60 (jmp dword [0x7494757c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiProcessSetup : C:\Windows\System32\gdi32full.dll @ 0x75ae4090 (jmp dword [0x74947694])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiDllInitialize : C:\Windows\System32\gdi32full.dll @ 0x75ae3ea0 (jmp dword [0x749442d8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnableEUDC : C:\Windows\System32\gdi32full.dll @ 0x75b1c570 (jmp dword [0x74947444])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertBitmapV5 : C:\Windows\System32\gdi32full.dll @ 0x75b3e180 (jmp dword [0x7494759c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertToDevmodeW : C:\Windows\System32\gdi32full.dll @ 0x75b39e20 (jmp dword [0x749475bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!MirrorRgn : C:\Windows\System32\gdi32full.dll @ 0x75b3a3b0 (jmp dword [0x749477e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b174c0 (jmp dword [0x749476dc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayout : C:\Windows\System32\gdi32full.dll @ 0x75b06e80 (jmp dword [0x749470a4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!ExcludeClipRect : C:\Windows\System32\gdi32full.dll @ 0x75b1abd0 (jmp dword [0x74947008])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CreateEllipticRgn : C:\Windows\System32\gdi32full.dll @ 0x75b39c40 (jmp dword [0x749472f4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!PolyPatBlt : C:\Windows\System32\gdi32full.dll @ 0x75b10850 (jmp dword [0x74947be4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetTextCharacterExtra : C:\Windows\System32\gdi32full.dll @ 0x75b07a40 (jmp dword [0x749471bc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetLayoutWidth : C:\Windows\System32\gdi32full.dll @ 0x75b18d20 (jmp dword [0x74947c70])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertAndCheckDC : C:\Windows\System32\gdi32full.dll @ 0x75b16730 (jmp dword [0x74947594])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBoundsRect : C:\Windows\System32\gdi32full.dll @ 0x75b16910 (jmp dword [0x74947c4c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyEnhMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b4dd60 (jmp dword [0x749472c8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!CopyMetaFileW : C:\Windows\System32\gdi32full.dll @ 0x75b44a70 (jmp dword [0x749472d0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharsetInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1b1d0 (jmp dword [0x749477ac])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!QueryFontAssocStatus : C:\Windows\System32\gdi32full.dll @ 0x75b196e0 (jmp dword [0x74947bfc])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharWidthInfo : C:\Windows\System32\gdi32full.dll @ 0x75b1ca20 (jmp dword [0x74947704])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceW : C:\Windows\System32\gdi32full.dll @ 0x75ae8930 (jmp dword [0x74947174])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsW : C:\Windows\System32\gdi32full.dll @ 0x75b15a30 (jmp dword [0x74947134])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetCharABCWidthsA : C:\Windows\System32\gdi32full.dll @ 0x75b36d40 (jmp dword [0x749476e4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!SetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b076a0 (jmp dword [0x749470e0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextFaceAliasW : C:\Windows\System32\gdi32full.dll @ 0x75ae8030 (jmp dword [0x749477b8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!EnumFontsW : C:\Windows\System32\gdi32full.dll @ 0x75b10e80 (jmp dword [0x749471a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b51010 (jmp dword [0x749475c0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiCreateLocalMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b51030 (jmp dword [0x749475c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertEnhMetaFile : C:\Windows\System32\gdi32full.dll @ 0x75b50f20 (jmp dword [0x749475a8])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiConvertMetaFilePict : C:\Windows\System32\gdi32full.dll @ 0x75b50f90 (jmp dword [0x749475b0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75afd6e0 (jmp dword [0x74947178])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!TextOutW : C:\Windows\System32\gdi32full.dll @ 0x75b47680 (jmp dword [0x74947184])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetWindowExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecf90 (jmp dword [0x749470f0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetViewportExtEx : C:\Windows\System32\gdi32full.dll @ 0x75aecec0 (jmp dword [0x749477c4])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetBkMode : C:\Windows\System32\gdi32full.dll @ 0x75b043f0 (jmp dword [0x7494706c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCharDimensions : C:\Windows\System32\gdi32full.dll @ 0x75b13cb0 (jmp dword [0x7494762c])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextCharset : C:\Windows\System32\gdi32full.dll @ 0x75b17c90 (jmp dword [0x749471a0])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GdiGetCodePage : C:\Windows\System32\gdi32full.dll @ 0x75b11760 (jmp dword [0x74947630])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!GetTextExtentPointW : C:\Windows\System32\gdi32full.dll @ 0x75afaf60 (jmp dword [0x74947194])
[IAT:Inl] (iexplore.exe @ user32.dll) gdi32!OffsetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b14060 (jmp dword [0x749470e8])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!InvalidateRect : C:\Windows\System32\win32u.dll @ 0x753124c0 (jmp dword [0x74bffb9c])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetKeyboardLayoutList : C:\Windows\System32\win32u.dll @ 0x75312a00 (jmp dword [0x74bffc8c])
[IAT:Addr(Microsoft)] (iexplore.exe @ gdi32full.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ gdi32full.dll) user32!GetDC : C:\Windows\System32\win32u.dll @ 0x75312520 (jmp dword [0x74bffcc4])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetForegroundWindow : C:\Windows\System32\win32u.dll @ 0x75312840 (jmp dword [0x74bffcac])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75312bf0 (jmp dword [0x74bffc88])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!DestroyWindow : C:\Windows\System32\win32u.dll @ 0x75312e40 (jmp dword [0x74bffd50])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!ShowWindow : C:\Windows\System32\win32u.dll @ 0x753129f0 (jmp dword [0x74bffa18])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!EndPaint : C:\Windows\System32\win32u.dll @ 0x75312610 (jmp dword [0x74bffd00])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!BeginPaint : C:\Windows\System32\win32u.dll @ 0x753125f0 (jmp dword [0x74bffdb8])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetWindowPos : C:\Windows\System32\win32u.dll @ 0x753126c0 (jmp dword [0x74bffa2c])
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!SetCapture : C:\Windows\System32\win32u.dll @ 0x75312910 (jmp dword [0x74bffab8])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ imm32.dll) user32!GetFocus : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcessMitigationPolicy : C:\Windows\System32\KERNELBASE.dll @ 0x7603af60
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetThreadLocale : C:\Windows\System32\KERNELBASE.dll @ 0x7603b480 (jmp dword [0x75a01060])
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!GetSystemDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c630 (jmp dword [0x75a01064])
[IAT:Addr] (iexplore.exe @ imm32.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr(Microsoft)] (iexplore.exe @ imm32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl] (iexplore.exe @ imm32.dll) kernel32!RtlCaptureContext : C:\Windows\System32\ntdll.dll @ 0x777d2e00 (jmp dword [0x75a014c4])
[IAT:Inl] (iexplore.exe @ imm32.dll) gdi32!GetTextExtentPoint32W : C:\Windows\System32\gdi32full.dll @ 0x75afe460 (jmp dword [0x74947198])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CopyFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7603f280 (jmp dword [0x75a00ea4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempPathW : C:\Windows\System32\KERNELBASE.dll @ 0x7603d040 (jmp dword [0x75a00de4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetTempFileNameW : C:\Windows\System32\KERNELBASE.dll @ 0x7604f170 (jmp dword [0x75a00ddc])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bb760
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindNextStreamW : C:\Windows\System32\KERNELBASE.dll @ 0x760bba70
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenMutexW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b3d0 (jmp dword [0x75a0155c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76034d50 (jmp dword [0x75a01600])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLCID : C:\Windows\System32\KERNELBASE.dll @ 0x7601c490 (jmp dword [0x75a01030])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x76035480 (jmp dword [0x75a01604])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionAndSpinCount : C:\Windows\System32\KERNELBASE.dll @ 0x76034c60 (jmp dword [0x75a0154c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604fe20 (jmp dword [0x75a00e38])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetFinalPathNameByHandleW : C:\Windows\System32\KERNELBASE.dll @ 0x76046b60 (jmp dword [0x75a00dc8])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLocalTime : C:\Windows\System32\KERNELBASE.dll @ 0x760344b0 (jmp dword [0x75a015f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToSystemTime : C:\Windows\System32\KERNELBASE.dll @ 0x760345d0 (jmp dword [0x75a01668])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FileTimeToLocalFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604a210 (jmp dword [0x75a00d20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc440 (jmp dword [0x75a016cc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateMutexA : C:\Windows\System32\KERNELBASE.dll @ 0x76051fb0 (jmp dword [0x75a01530])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjects : C:\Windows\System32\KERNELBASE.dll @ 0x76031c30 (jmp dword [0x75a015b8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetFileAttributesW : C:\Windows\System32\KERNELBASE.dll @ 0x76057af0 (jmp dword [0x75a00e28])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventExW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b670 (jmp dword [0x75a01544])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateSemaphoreW : C:\Windows\System32\KERNELBASE.dll @ 0x7603b040 (jmp dword [0x75a015b4])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimerEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034ec0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CancelWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045b70 (jmp dword [0x75a01540])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76050660 (jmp dword [0x75a01034])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultLangID : C:\Windows\System32\KERNELBASE.dll @ 0x76047db0 (jmp dword [0x75a01068])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!WaitForMultipleObjectsEx : C:\Windows\System32\KERNELBASE.dll @ 0x76031c60 (jmp dword [0x75a0157c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetWaitableTimer : C:\Windows\System32\KERNELBASE.dll @ 0x76045120 (jmp dword [0x75a01574])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FindFirstFileW : C:\Windows\System32\KERNELBASE.dll @ 0x7602c070 (jmp dword [0x75a00d44])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDriveTypeW : C:\Windows\System32\KERNELBASE.dll @ 0x76035950 (jmp dword [0x75a00d7c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateEventA : C:\Windows\System32\KERNELBASE.dll @ 0x7602b5d0 (jmp dword [0x75a0153c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateFile2 : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6a0 (jmp dword [0x75a00db4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemWow64DirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76057ee0 (jmp dword [0x75a016d8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LocalFileTimeToFileTime : C:\Windows\System32\KERNELBASE.dll @ 0x7604edf0 (jmp dword [0x75a00dfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!SetEndOfFile : C:\Windows\System32\KERNELBASE.dll @ 0x7603d520 (jmp dword [0x75a00e20])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetDiskFreeSpaceExW : C:\Windows\System32\KERNELBASE.dll @ 0x7603bbe0 (jmp dword [0x75a00d70])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!UnlockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604c6d0 (jmp dword [0x75a00e40])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!LockFile : C:\Windows\System32\KERNELBASE.dll @ 0x7604cb60 (jmp dword [0x75a00e00])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetLogicalDriveStringsW : C:\Windows\System32\KERNELBASE.dll @ 0x76059010 (jmp dword [0x75a00dd4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!QueryDosDeviceW : C:\Windows\System32\KERNELBASE.dll @ 0x76056b40 (jmp dword [0x75a00e08])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetVersion : C:\Windows\System32\KERNELBASE.dll @ 0x76057ca0 (jmp dword [0x75a01610])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetSystemDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x7603e150 (jmp dword [0x75a00a3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!InitializeCriticalSectionEx : C:\Windows\System32\KERNELBASE.dll @ 0x76034fa0 (jmp dword [0x75a01550])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!ReleaseActCtx : C:\Windows\System32\KERNELBASE.dll @ 0x76057c50 (jmp dword [0x75a014f4])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!GetUserDefaultUILanguage : C:\Windows\System32\KERNELBASE.dll @ 0x76034390 (jmp dword [0x75a00a40])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!OpenEventW : C:\Windows\System32\KERNELBASE.dll @ 0x7602b720 (jmp dword [0x75a01558])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!RemoveDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x7603e600 (jmp dword [0x75a00e1c])
[IAT:Inl(Microsoft)] (iexplore.exe @ ieframe.dll) kernel32!CreateDirectoryW : C:\Windows\System32\KERNELBASE.dll @ 0x76039bb0 (jmp dword [0x75a00db8])
[IAT:Addr] (iexplore.exe @ ieframe.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ ieframe.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b43e80 (jmp dword [0x7494704c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiTransparentBlt : C:\Windows\System32\gdi32full.dll @ 0x75b182f0 (jmp dword [0x74947108])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiGradientFill : C:\Windows\System32\gdi32full.dll @ 0x75b134a0 (jmp dword [0x7494710c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiAlphaBlend : C:\Windows\System32\gdi32full.dll @ 0x75b107c0 (jmp dword [0x749470cc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetBrushOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b0cb10 (jmp dword [0x74947104])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateHalftonePalette : C:\Windows\System32\gdi32full.dll @ 0x75b1b1b0 (jmp dword [0x74947304])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!PtInRegion : C:\Windows\System32\gdi32full.dll @ 0x75b3a610 (jmp dword [0x7494436c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateFontW : C:\Windows\System32\gdi32full.dll @ 0x75b16130 (jmp dword [0x749471b8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GdiFlush : C:\Windows\System32\gdi32full.dll @ 0x75b13800 (jmp dword [0x74947060])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCPenColor : C:\Windows\System32\gdi32full.dll @ 0x75b441a0 (jmp dword [0x74947c5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!SetDCBrushColor : C:\Windows\System32\gdi32full.dll @ 0x75b44000 (jmp dword [0x7494701c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!GetTextExtentExPointW : C:\Windows\System32\gdi32full.dll @ 0x75b17ea0 (jmp dword [0x74947168])
[IAT:Inl] (iexplore.exe @ ieframe.dll) gdi32!CreateDIBPatternBrushPt : C:\Windows\System32\gdi32full.dll @ 0x75b39c00 (jmp dword [0x74947124])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!MoveWindow : C:\Windows\System32\win32u.dll @ 0x75312a50 (jmp dword [0x74bffb58])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WaitMessage : C:\Windows\System32\win32u.dll @ 0x75312540 (jmp dword [0x74bff9b4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackPopupMenuEx : C:\Windows\System32\win32u.dll @ 0x753169b0 (jmp dword [0x74bff9f4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DeleteMenu : C:\Windows\System32\win32u.dll @ 0x75313030 (jmp dword [0x74bffd5c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!CopyAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75312740 (jmp dword [0x74bffd70])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!KillTimer : C:\Windows\System32\win32u.dll @ 0x75312630 (jmp dword [0x74bffb78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetDoubleClickTime : C:\Windows\System32\win32u.dll @ 0x75312fd0 (jmp dword [0x74bffcb0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!WindowFromPoint : C:\Windows\System32\win32u.dll @ 0x753125c0 (jmp dword [0x74bff9ac])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageTime : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!AttachThreadInput : C:\Windows\System32\win32u.dll @ 0x75313320 (jmp dword [0x74bffdbc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetSystemMenu : C:\Windows\System32\win32u.dll @ 0x75312a80 (jmp dword [0x74bffc1c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!FlashWindowEx : C:\Windows\System32\win32u.dll @ 0x75315bd0 (jmp dword [0x74bffcf4])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowDC : C:\Windows\System32\win32u.dll @ 0x75312ab0 (jmp dword [0x74bffbf8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!TrackMouseEvent : C:\Windows\System32\win32u.dll @ 0x75313210 (jmp dword [0x74bff9f8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SendInput : C:\Windows\System32\win32u.dll @ 0x75312c90 (jmp dword [0x74bffad8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetGUIThreadInfo : C:\Windows\System32\win32u.dll @ 0x75313450 (jmp dword [0x74bffca8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x753131b0 (jmp dword [0x74bffbe8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetTitleBarInfo : C:\Windows\System32\win32u.dll @ 0x75312d60 (jmp dword [0x74bffc14])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetKeyboardState : C:\Windows\System32\win32u.dll @ 0x75313350 (jmp dword [0x74bffa78])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!PrintWindow : C:\Windows\System32\win32u.dll @ 0x753163a0 (jmp dword [0x74bffb38])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetComboBoxInfo : C:\Windows\System32\win32u.dll @ 0x75315c60 (jmp dword [0x74bffcd0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RedrawWindow : C:\Windows\System32\win32u.dll @ 0x753125b0 (jmp dword [0x74bffb24])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMessageExtraInfo : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ShowScrollBar : C:\Windows\System32\win32u.dll @ 0x75312850 (jmp dword [0x74bffa20])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetWindowPlacement : C:\Windows\System32\win32u.dll @ 0x75313280 (jmp dword [0x74bffa30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetActiveWindow : C:\Windows\System32\win32u.dll @ 0x75313260 (jmp dword [0x74bffac8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ChangeWindowMessageFilterEx : C:\Windows\System32\win32u.dll @ 0x753158f0 (jmp dword [0x74bffda0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EnumDisplayMonitors : C:\Windows\System32\win32u.dll @ 0x75312920 (jmp dword [0x74bffcfc])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetClipCursor : C:\Windows\System32\win32u.dll @ 0x75315c30 (jmp dword [0x74bffcd8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!ValidateRect : C:\Windows\System32\win32u.dll @ 0x75313140 (jmp dword [0x74bff9c0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCaretBlinkTime : C:\Windows\System32\win32u.dll @ 0x753133a0 (jmp dword [0x74bffce0])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!EndMenu : C:\Windows\System32\win32u.dll @ 0x75315bb0 (jmp dword [0x74bffd04])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75316760 (jmp dword [0x74bffa74])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetRawInputData : C:\Windows\System32\win32u.dll @ 0x75315f30 (jmp dword [0x74bffc30])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RegisterRawInputDevices : C:\Windows\System32\win32u.dll @ 0x753164c0 (jmp dword [0x74bffb0c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetCursor : C:\Windows\System32\win32u.dll @ 0x75312480 (call dword [0x74bff994])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetMenuItemRect : C:\Windows\System32\win32u.dll @ 0x75315e00 (jmp dword [0x74bffc74])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!RemoveMenu : C:\Windows\System32\win32u.dll @ 0x75313400 (jmp dword [0x74bffae8])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!DestroyMenu : C:\Windows\System32\win32u.dll @ 0x75313230 (jmp dword [0x74bffd54])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetFocus : C:\Windows\System32\win32u.dll @ 0x75312990 (jmp dword [0x74bffa8c])
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!SetMenuDefaultItem : C:\Windows\System32\win32u.dll @ 0x75313480 (jmp dword [0x74bffa68])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ ieframe.dll) user32!GetAncestor : C:\Windows\System32\win32u.dll @ 0x75312f90 (jmp dword [0x74bffcec])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ ieframe.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesA : C:\Windows\System32\gdi32full.dll @ 0x75b37280 (jmp dword [0x7494774c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetGlyphIndicesW : C:\Windows\System32\gdi32full.dll @ 0x75b18460 (jmp dword [0x7494714c])
[IAT:Inl] (iexplore.exe @ shlwapi.dll) gdi32!GetTextExtentExPointI : C:\Windows\System32\gdi32full.dll @ 0x75b37890 (jmp dword [0x7494719c])
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shlwapi.dll) user32!DialogBoxParamA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230830
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!GetFullPathNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bbe80 (jmp dword [0x75a00dcc])
[IAT:Inl(Microsoft)] (iexplore.exe @ ole32.dll) kernel32!CreateFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d600 (jmp dword [0x75a00db0])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!OffsetViewportOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b12db0 (jmp dword [0x74947088])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetWindowOrgEx : C:\Windows\System32\gdi32full.dll @ 0x75b071e0 (jmp dword [0x749470ec])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!EnumFontFamiliesExW : C:\Windows\System32\gdi32full.dll @ 0x75b10f90 (jmp dword [0x74947188])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayEnhMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b04c10 (jmp dword [0x74947bd4])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetWinMetaFileBits : C:\Windows\System32\gdi32full.dll @ 0x75b4e4b0 (jmp dword [0x74947c9c])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!PlayMetaFileRecord : C:\Windows\System32\gdi32full.dll @ 0x75b0a230 (jmp dword [0x74947bd8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetGraphicsMode : C:\Windows\System32\gdi32full.dll @ 0x75b13b90 (jmp dword [0x74947754])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!GetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b39fa0 (jmp dword [0x749476d8])
[IAT:Inl] (iexplore.exe @ ole32.dll) gdi32!SetBitmapDimensionEx : C:\Windows\System32\gdi32full.dll @ 0x75b3a0a0 (jmp dword [0x74947c44])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!CheckProcessForClipboardAccess : C:\Windows\System32\win32u.dll @ 0x75315910 (jmp dword [0x74bffd9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ ole32.dll) user32!SetWindowWord : C:\Windows\System32\win32u.dll @ 0x753132e0 (jmp dword [0x74bffa24])
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ ole32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetAutoRotationState : C:\Windows\System32\win32u.dll @ 0x75315c00 (jmp dword [0x74bffce8])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetCurrentInputMessageSource : C:\Windows\System32\win32u.dll @ 0x75315c70 (jmp dword [0x74bffccc])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!ShutdownBlockReasonDestroy : C:\Windows\System32\win32u.dll @ 0x75316940 (jmp dword [0x74bffa10])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!UnhookWinEvent : C:\Windows\System32\win32u.dll @ 0x753134b0 (jmp dword [0x74bff9ec])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!LockWindowUpdate : C:\Windows\System32\win32u.dll @ 0x753134c0 (jmp dword [0x74bffb6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetShellWindowEx : C:\Windows\System32\win32u.dll @ 0x75316820 (jmp dword [0x74bffa50])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CreateAcceleratorTableW : C:\Windows\System32\win32u.dll @ 0x75313370 (jmp dword [0x74bffd6c])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetCoalescableTimer : C:\Windows\System32\win32u.dll @ 0x75312600 (jmp dword [0x74bffaac])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetPointerDevices : C:\Windows\System32\win32u.dll @ 0x75315e80 (jmp dword [0x74bffc50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!CloseDesktop : C:\Windows\System32\win32u.dll @ 0x75312ed0 (jmp dword [0x74bffd84])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!OpenInputDesktop : C:\Windows\System32\win32u.dll @ 0x75316350 (jmp dword [0x74bffb50])
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ shell32.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetWindowBand : C:\Windows\System32\win32u.dll @ 0x75315fd0 (jmp dword [0x74bffc04])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!SetGestureConfig : C:\Windows\System32\win32u.dll @ 0x753166f0 (jmp dword [0x74bffa88])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetUserObjectInformationW : C:\Windows\System32\win32u.dll @ 0x75312b30 (jmp dword [0x74bffc08])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetProcessWindowStation : C:\Windows\System32\win32u.dll @ 0x753126a0 (jmp dword [0x74bffc38])
[IAT:Inl] (iexplore.exe @ shell32.dll) user32!GetThreadDesktop : C:\Windows\System32\win32u.dll @ 0x75312ca0 (jmp dword [0x74bffc18])
[IAT:Inl] (iexplore.exe @ shell32.dll) gdi32!PlgBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46ae0 (jmp dword [0x749470e4])
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!MessageBoxIndirectW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230d50
[IAT:Addr(Microsoft)] (iexplore.exe @ windows.storage.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!MaskBlt : C:\Windows\System32\gdi32full.dll @ 0x75b46710 (jmp dword [0x749477e0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetDIBColorTable : C:\Windows\System32\gdi32full.dll @ 0x75b47870 (jmp dword [0x749470dc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!SetPixelV : C:\Windows\System32\gdi32full.dll @ 0x75b47210 (jmp dword [0x74947c7c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetCharWidthW : C:\Windows\System32\gdi32full.dll @ 0x75b125d0 (jmp dword [0x7494713c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) gdi32!GetNearestColor : C:\Windows\System32\gdi32full.dll @ 0x75b16940 (jmp dword [0x7494777c])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetDCEx : C:\Windows\System32\win32u.dll @ 0x75312d90 (jmp dword [0x74bffcc0])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetScrollBarInfo : C:\Windows\System32\win32u.dll @ 0x75312da0 (jmp dword [0x74bffc20])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!ShowWindowAsync : C:\Windows\System32\win32u.dll @ 0x75313610 (jmp dword [0x74bffa14])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!IsTopLevelWindow : C:\Windows\System32\win32u.dll @ 0x75316210 (jmp dword [0x74bffb84])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!GetCaretPos : C:\Windows\System32\win32u.dll @ 0x75315c20 (jmp dword [0x74bffcdc])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!InvalidateRgn : C:\Windows\System32\win32u.dll @ 0x753130f0 (jmp dword [0x74bffb98])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!RegisterTouchHitTestingWindow : C:\Windows\System32\win32u.dll @ 0x75316510 (jmp dword [0x74bffaf8])
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!DragDetect : C:\Windows\System32\win32u.dll @ 0x75315aa0 (jmp dword [0x74bffd40])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ comctl32.dll) user32!BlockInput : C:\Windows\System32\win32u.dll @ 0x75315870 (jmp dword [0x74bffdb4])
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!CreateWindowExA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d260
[IAT:Addr(Microsoft)] (iexplore.exe @ comctl32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Inl(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!GetFileInformationByHandle : C:\Windows\System32\KERNELBASE.dll @ 0x7603b170 (jmp dword [0x75a00d90])
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!ExitThread : C:\Windows\System32\ntdll.dll @ 0x777b19d0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!InitializeProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603e960
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!DeleteProcThreadAttributeList : C:\Windows\System32\KERNELBASE.dll @ 0x7603eed0
[IAT:Addr] (iexplore.exe @ IEShims.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ IEShims.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!DialogBoxIndirectParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230760
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ comdlg32.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Inl] (iexplore.exe @ comdlg32.dll) user32!ClipCursor : C:\Windows\System32\win32u.dll @ 0x75315960 (jmp dword [0x74bffd88])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!GetCharWidth32W : C:\Windows\System32\gdi32full.dll @ 0x75b36e00 (jmp dword [0x749476f4])
[IAT:Inl] (iexplore.exe @ comdlg32.dll) gdi32!CreateDiscardableBitmap : C:\Windows\System32\gdi32full.dll @ 0x75b39c30 (jmp dword [0x749472f0])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GetRandomRgn : C:\Windows\System32\gdi32full.dll @ 0x75b15c40 (jmp dword [0x74944300])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!GdiDrawStream : C:\Windows\System32\gdi32full.dll @ 0x75b13580 (jmp dword [0x749475d4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!SetBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a890 (jmp dword [0x74947c40])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ExtCreatePen : C:\Windows\System32\gdi32full.dll @ 0x75b18db0 (jmp dword [0x74947530])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!AbortPath : C:\Windows\System32\gdi32full.dll @ 0x75b478f0 (jmp dword [0x7494725c])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!StrokeAndFillPath : C:\Windows\System32\gdi32full.dll @ 0x75b47a70 (jmp dword [0x74947cb4])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!CreateSessionMappedDIBSection : C:\Windows\System32\gdi32full.dll @ 0x75b3a710 (jmp dword [0x74947318])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) gdi32!ClearBitmapAttributes : C:\Windows\System32\gdi32full.dll @ 0x75b3a6d0 (jmp dword [0x749472ac])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!CalcMenuBar : C:\Windows\System32\win32u.dll @ 0x75312de0 (jmp dword [0x74bffdac])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!PaintMenuBar : C:\Windows\System32\win32u.dll @ 0x75313340 (jmp dword [0x74bffb48])
[IAT:Inl] (iexplore.exe @ uxtheme.dll) user32!GetMenuBarInfo : C:\Windows\System32\win32u.dll @ 0x75313080 (jmp dword [0x74bffc78])
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ uxtheme.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolWorkCallbacks : C:\Windows\System32\ntdll.dll @ 0x777b42d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x777b4300
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SubmitThreadpoolWork : C:\Windows\System32\ntdll.dll @ 0x7778ad60
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitOnceInitialize : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!SetThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777b4100
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!WaitForThreadpoolTimerCallbacks : C:\Windows\System32\ntdll.dll @ 0x77788520
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!CloseThreadpoolTimer : C:\Windows\System32\ntdll.dll @ 0x777866e0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!TerminateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622126a0
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!DeleteFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c5f0 (jmp dword [0x75a00cfc])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!SwitchToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x76049e70 (jmp dword [0x75a00cf8])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604a2f0 (jmp dword [0x75a00d04])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertThreadToFiber : C:\Windows\System32\KERNELBASE.dll @ 0x7604c4e0 (jmp dword [0x75a00d0c])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!ConvertFiberToThread : C:\Windows\System32\KERNELBASE.dll @ 0x7604de70 (jmp dword [0x75a00d10])
[IAT:Inl(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!GetDiskFreeSpaceW : C:\Windows\System32\KERNELBASE.dll @ 0x760bc140 (jmp dword [0x75a00d74])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryWhenCallbackReturns : C:\Windows\System32\ntdll.dll @ 0x777b4240
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeSRWLock : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778f9d0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockShared : C:\Windows\System32\ntdll.dll @ 0x7778fa90
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl] (iexplore.exe @ mshtml.dll) kernel32!WTSGetActiveConsoleSessionId : C:\Windows\System32\ntdll.dll @ 0x7779fce0 (jmp dword [0x75a019b0])
[IAT:Addr] (iexplore.exe @ mshtml.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!CreateHatchBrush : C:\Windows\System32\gdi32full.dll @ 0x75b39d10 (jmp dword [0x74947308])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetFontUnicodeRanges : C:\Windows\System32\gdi32full.dll @ 0x75b1b1c0 (jmp dword [0x74947748])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetGlyphOutlineW : C:\Windows\System32\gdi32full.dll @ 0x75b13080 (jmp dword [0x74947150])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!GetOutlineTextMetricsW : C:\Windows\System32\gdi32full.dll @ 0x75aecc70 (jmp dword [0x74947158])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!AddFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3af20 (jmp dword [0x749471b4])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!RemoveFontMemResourceEx : C:\Windows\System32\gdi32full.dll @ 0x75b3c040 (jmp dword [0x74947190])
[IAT:Inl] (iexplore.exe @ mshtml.dll) gdi32!EnumObjects : C:\Windows\System32\gdi32full.dll @ 0x75b39d30 (jmp dword [0x74947058])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CallNextHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212d40
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetLayeredWindowAttributes : C:\Windows\System32\win32u.dll @ 0x75315dd0 (jmp dword [0x74bffc84])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!MessageBoxW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230e20
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!DialogBoxParamW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230920
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!GetCursorInfo : C:\Windows\System32\win32u.dll @ 0x75315c90 (jmp dword [0x74bffcc8])
[IAT:Inl] (iexplore.exe @ mshtml.dll) user32!ChildWindowFromPointEx : C:\Windows\System32\win32u.dll @ 0x75315940 (jmp dword [0x74bffd90])
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!EnableWindow : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62213d40
[IAT:Addr(Microsoft)] (iexplore.exe @ mshtml.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteEx : C:\Windows\System32\ntdll.dll @ 0x77838d80
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventSetInformation : C:\Windows\System32\ntdll.dll @ 0x7779ef40
[IAT:Addr] (iexplore.exe @ mshtml.dll) advapi32!EventWriteTransfer : C:\Windows\System32\ntdll.dll @ 0x777a7480
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetWindowCompositionAttribute : C:\Windows\System32\win32u.dll @ 0x75315fe0 (jmp dword [0x74bffc00])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!UpdateDefaultDesktopThumbnail : C:\Windows\System32\win32u.dll @ 0x75316a40 (jmp dword [0x74bff9d4])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!SetWindowCompositionTransition : C:\Windows\System32\win32u.dll @ 0x753168b0 (jmp dword [0x74bffa3c])
[IAT:Inl] (iexplore.exe @ dwmapi.dll) user32!GetGuiResources : C:\Windows\System32\win32u.dll @ 0x75315d30 (jmp dword [0x74bffca0])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ msctf.dll) user32!GetInputLocaleInfo : C:\Windows\System32\win32u.dll @ 0x75315d70 (jmp dword [0x74bffc9c])
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ msctf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Inl(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!SetFilePointerEx : C:\Windows\System32\KERNELBASE.dll @ 0x7603a010 (jmp dword [0x75a00e34])
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ aticfx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ aticfx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Inl(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!DebugBreak : C:\Windows\System32\KERNELBASE.dll @ 0x760b48d0 (jmp dword [0x75a00c88])
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ atiuxpag.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atiuxpag.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!SleepConditionVariableCS : C:\Windows\System32\KERNELBASE.dll @ 0x760b4550
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!VerSetConditionMask : C:\Windows\System32\ntdll.dll @ 0x777af950
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae6d0
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetFileAttributesA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d930 (jmp dword [0x75a00d80])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateDirectoryA : C:\Windows\System32\KERNELBASE.dll @ 0x76039b70 (jmp dword [0x75a00dbc])
[IAT:Inl(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!FindFirstFileA : C:\Windows\System32\KERNELBASE.dll @ 0x7603d1f0 (jmp dword [0x75a00d34])
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeAllConditionVariable : C:\Windows\System32\ntdll.dll @ 0x777ae1e0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!WakeConditionVariable : C:\Windows\System32\ntdll.dll @ 0x77822cc0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!CreateThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x622115e0
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!ExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212360
[IAT:Addr(Microsoft)] (iexplore.exe @ atidxx32.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ atidxx32.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventRegister : C:\Windows\System32\ntdll.dll @ 0x7779e380
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventUnregister : C:\Windows\System32\ntdll.dll @ 0x7777def0
[IAT:Addr] (iexplore.exe @ atidxx32.dll) advapi32!EventWrite : C:\Windows\System32\ntdll.dll @ 0x777a7450
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapSize : C:\Windows\System32\ntdll.dll @ 0x7777ce30
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ mdnsNSP.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!FatalAppExitA : C:\Windows\System32\KERNELBASE.dll @ 0x760b8c30 (jmp dword [0x75a00a88])
[IAT:Inl(Microsoft)] (iexplore.exe @ mdnsNSP.dll) kernel32!SetConsoleCtrlHandler : C:\Windows\System32\KERNELBASE.dll @ 0x7603e350 (jmp dword [0x75a00b84])
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!InitOnceExecuteOnce : C:\Windows\System32\KERNELBASE.dll @ 0x760336c0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DecodePointer : C:\Windows\System32\ntdll.dll @ 0x777acd90
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EncodePointer : C:\Windows\System32\ntdll.dll @ 0x777ad040
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!QueryDepthSList : C:\Windows\System32\ntdll.dll @ 0x777b17d0
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedFlushSList : C:\Windows\System32\ntdll.dll @ 0x777b3580
[IAT:Addr] (iexplore.exe @ ieui.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212490
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ ieui.dll) user32!SetWindowLongW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212db0
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!ModifyWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b05a80 (jmp dword [0x749477e8])
[IAT:Inl] (iexplore.exe @ ieui.dll) gdi32!GetWorldTransform : C:\Windows\System32\gdi32full.dll @ 0x75b174f0 (jmp dword [0x74947084])
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!UnregisterTraceGuids : C:\Windows\System32\ntdll.dll @ 0x7777dea0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceLoggerHandle : C:\Windows\System32\ntdll.dll @ 0x777b6750
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableFlags : C:\Windows\System32\ntdll.dll @ 0x777b6bb0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!GetTraceEnableLevel : C:\Windows\System32\ntdll.dll @ 0x777b6be0
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!RegisterTraceGuidsA : C:\Windows\System32\ntdll.dll @ 0x777b6790
[IAT:Addr] (iexplore.exe @ ieui.dll) advapi32!TraceEvent : C:\Windows\System32\ntdll.dll @ 0x777bd520
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPushEntrySList : C:\Windows\System32\ntdll.dll @ 0x777acfd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InterlockedPopEntrySList : C:\Windows\System32\ntdll.dll @ 0x777adb50
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeSListHead : C:\Windows\System32\ntdll.dll @ 0x777b2870
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!FreeLibraryAndExitThread : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211570
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!SetConsoleTextAttribute : C:\Windows\System32\KERNELBASE.dll @ 0x76093c80 (jmp dword [0x75a00bf4])
[IAT:Inl(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetConsoleScreenBufferInfo : C:\Windows\System32\KERNELBASE.dll @ 0x76093770 (jmp dword [0x75a00c20])
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EncodeSystemPointer : C:\Windows\System32\ntdll.dll @ 0x777753d0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!InitializeCriticalSection : C:\Windows\System32\ntdll.dll @ 0x777a6bd0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!DeleteCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779f450
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!LeaveCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778fea0
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!EnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7778ff20
[IAT:Addr] (iexplore.exe @ jscript9.dll) kernel32!TryEnterCriticalSection : C:\Windows\System32\ntdll.dll @ 0x7779c8b0
[IAT:Addr(Microsoft)] (iexplore.exe @ jscript9.dll) kernel32!RaiseFailFastException : C:\Windows\System32\KERNELBASE.dll @ 0x760bcfc0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6221d3d0
[IAT:Addr(Microsoft)] (iexplore.exe @ msimtf.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!SetWindowsHookExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211f80
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!UnhookWindowsHookEx : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211ef0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!RegisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316480 (jmp dword [0x74bffb18])
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!UnregisterHotKey : C:\Windows\System32\win32u.dll @ 0x75316a10 (jmp dword [0x74bff9e0])
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!CreateWindowExW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62211890
[IAT:Addr(Microsoft)] (iexplore.exe @ oleacc.dll) user32!DefWindowProcW : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62212ca0
[IAT:Inl] (iexplore.exe @ oleacc.dll) user32!MenuItemFromPoint : C:\Windows\System32\win32u.dll @ 0x75316300 (jmp dword [0x74bffb5c])
[IAT:Addr] (iexplore.exe @ sxs.dll) kernel32!ResolveDelayLoadedAPI : C:\Windows\System32\ntdll.dll @ 0x7778e5d0
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempFileNameA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc460 (jmp dword [0x75a00e54])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetProcAddress : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x6220f510
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapReAlloc : C:\Windows\System32\ntdll.dll @ 0x77799cb0
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!HeapAlloc : C:\Windows\System32\ntdll.dll @ 0x77795b00
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!GetTempPathA : C:\Windows\System32\KERNELBASE.dll @ 0x760bc590 (jmp dword [0x75a00e60])
[IAT:Inl(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!DeleteFileA : C:\Windows\System32\KERNELBASE.dll @ 0x76054340 (jmp dword [0x75a00d3c])
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceBeginInitialize : C:\Windows\System32\KERNELBASE.dll @ 0x7602c870
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!ReleaseSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b380
[IAT:Addr(Microsoft)] (iexplore.exe @ t2embed.dll) kernel32!InitOnceComplete : C:\Windows\System32\KERNELBASE.dll @ 0x7603e110
[IAT:Addr] (iexplore.exe @ t2embed.dll) kernel32!AcquireSRWLockExclusive : C:\Windows\System32\ntdll.dll @ 0x7778b500
[IAT:Inl] (iexplore.exe @ t2embed.dll) gdi32!CreateScalableFontResourceA : C:\Windows\System32\gdi32full.dll @ 0x75b3b2d0 (jmp dword [0x74947310])
[IAT:Addr(Microsoft)] (iexplore.exe @ wintrust.dll) user32!MessageBoxA : C:\Program Files (x86)\Internet Explorer\IEShims.dll @ 0x62230a10

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ MBR Check : ¤¤¤
+++++ PhysicalDrive0:  +++++
--- User ---
[MBR] f86f4a6d732d5d11731309772e1fbe7f
[BSP] 2bf3dd60e501e1f0f760c942b8d1b006 : Empty MBR Code
Partition table:
0 - [SYSTEM][MAN-MOUNT] Basic data partition | Offset (sectors): 2048 | Size: 1023 MB
1 - [MAN-MOUNT] EFI system partition | Offset (sectors): 2097152 | Size: 360 MB
2 - [MAN-MOUNT] Microsoft reserved partition | Offset (sectors): 2834432 | Size: 128 MB
3 - Basic data partition | Offset (sectors): 3096576 | Size: 1886686 MB
4 - [SYSTEM][MAN-MOUNT]  | Offset (sectors): 3867029504 | Size: 450 MB
5 - [SYSTEM] Basic data partition | Offset (sectors): 3867951104 | Size: 19076 MB
User = LL1 ... OK
User = LL2 ... OK

+++++ PhysicalDrive1:  +++++
--- User ---
[MBR] 1c42ac96cea7b70222a78c22ed7f378f
[BSP] 6f61b52460ecc86ec118b4d775eee70e : Unknown|VT.Unknown MBR Code
Partition table:
0 - [XXXXXX] UNKNOWN (0x6e) [VISIBLE] Offset (sectors): 1948285285 | Size: 831044 MB
3 - [XXXXXX] UNKNOWN (0x0) [VISIBLE] Offset (sectors): 28049408 | Size: 0 MB
User = LL1 ... OK
Error reading LL2 MBR! ([32] The request is not supported. )


  • 0

Advertisements


#32
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

aswmbr is from Avast.  This is Kaspersky

 

<script type="text/javascript"> //</script>I did run the Kaspersky, but it simply asks, after locating several things, non of which I could copy and paste, to upgrade. no other options. I'll go now, to look at your instructions, maybe you gave me a work around for that, like log files or something.


  • 0

#33
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

I went to the Kaspersky site.  Clicked on Download now then it went to another page that said if it doesn't start to hit Download Now again which I did.  It downloaded.  Show in Folder, right clicked and Run As Admin.  waited about 30 seconds then Continue then SKIP and it downloaded a great big file which I assume it will use for the scan.  I don't have time today to run the whole scan.  Have to leave in a few minutes.


  • 0

#34
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

I went to the Kaspersky site.  Clicked on Download now then it went to another page that said if it doesn't start to hit Download Now again which I did.  It downloaded.  Show in Folder, right clicked and Run As Admin.  waited about 30 seconds then Continue then SKIP and it downloaded a great big file which I assume it will use for the scan.  I don't have time today to run the whole scan.  Have to leave in a few minutes.

 

<script type="text/javascript"> yes, I did all that, and it then gives me an installed complete program. I ran the complete scan, and then it says 14 items found, but they aren't in a log, they are in an interactive interface. //</script>


  • 0

#35
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Also, I just found this lot, not sure what it is, it's in the C drive windows folder, it's called CFRO notepad file anyway, it's date was yesterday, so I assume something we did log seemed relevant so I posted it.

 

9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSDRV.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSDRV.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSUI.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSUI.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSUI.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSWZRD.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSWZRD.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSTIFF.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSTIFF.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSRES.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSRES.DLL, 0xc000003a
9/30/2016 14:25:17 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\FXSAPI.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\FXSAPI.DLL, 0xc000003a
9/30/2016 14:25:17 - 1 Successful PFRO operations

10/27/2016 3:57:51 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
10/27/2016 3:57:51 - 1 Successful PFRO operations

11/4/2016 13:56:17 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
11/4/2016 13:56:17 - 20 Successful PFRO operations

11/16/2016 18:0:56 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\Update\1.3.47.1, |delete operation|, 0xc0000034
11/16/2016 18:0:56 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
11/16/2016 18:0:56 - 6 Successful PFRO operations

12/15/2016 9:27:39 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8048_16066\old_chrome.exe, |delete operation|, 0xc000003a
12/15/2016 9:27:39 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8048_16066, |delete operation|, 0xc0000034
12/15/2016 9:27:39 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp, |delete operation|, 0xc0000101
12/15/2016 9:27:39 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
12/15/2016 9:27:39 - 12 Successful PFRO operations

12/15/2016 17:39:14 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
12/15/2016 17:39:14 - 0 Successful PFRO operations

1/17/2017 9:33:15 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
1/17/2017 9:33:15 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
1/17/2017 9:33:15 - 1 Successful PFRO operations

2/1/2017 9:38:28 - PFRO Error: \??\C:\WINDOWS\SysWoW64\ACTIVE_X, |delete operation|, 0xc0000034
2/1/2017 9:38:28 - PFRO Error: \??\C:\ProgramData\Adobe\Setup\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}, |delete operation|, 0xc0000034
2/1/2017 9:38:28 - PFRO Error: \??\C:\WINDOWS\SysWoW64\ACTIVE_X, |delete operation|, 0xc0000034
2/1/2017 9:38:28 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
2/1/2017 9:38:28 - 0 Successful PFRO operations

2/10/2017 7:22:44 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
2/10/2017 7:22:44 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
2/10/2017 7:22:45 - 3 Successful PFRO operations

2/20/2017 9:19:20 - PFRO Error: \??\C:\WINDOWS\system32\DRIVERS\SET8262.tmp, !\??\C:\WINDOWS\system32\DRIVERS\EpfwLWF.sys, 0xc0000022
2/20/2017 9:19:21 - 126 Successful PFRO operations

2/28/2017 5:40:16 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
2/28/2017 5:40:16 - 0 Successful PFRO operations

3/10/2017 5:35:42 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
3/10/2017 5:35:42 - 2 Successful PFRO operations

3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\MXDWDRV.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\MXDWDRV.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PJLMON.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PJLMON.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PS5UI.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PS5UI.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PSCRIPT5.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PSCRIPT5.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\UNIDRV.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\UNIDRV.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\UNIDRVUI.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\UNIDRVUI.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\UNIRES.DLL, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\UNIRES.DLL, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PrintConfig.dll, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\New\mxdwdrv.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\mxdwdrv.dll, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll, 0xc000003a
3/27/2017 3:3:12 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
3/27/2017 3:3:12 - 5 Successful PFRO operations

4/14/2017 4:46:3 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
4/14/2017 4:46:7 - 494 Successful PFRO operations

4/17/2017 10:38:10 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll, 0xc000003a
4/17/2017 10:38:10 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PrintConfig.dll, 0xc000003a
4/17/2017 10:38:10 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
4/17/2017 10:38:10 - 0 Successful PFRO operations

4/25/2017 16:0:37 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
4/25/2017 16:0:37 - 1 Successful PFRO operations

5/10/2017 17:49:31 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_12080_15161\old_chrome.exe, |delete operation|, 0xc000003a
5/10/2017 17:49:31 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_12080_15161, |delete operation|, 0xc0000034
5/10/2017 17:49:31 - PFRO Error: \??\C:\Program Files (x86)\Google\Chrome\Temp, |delete operation|, 0xc0000101
5/10/2017 17:49:31 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
5/10/2017 17:49:31 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
5/10/2017 17:49:31 - 7 Successful PFRO operations

5/21/2017 10:23:7 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\x64\3\PrintConfig.dll, 0xc000003a
5/21/2017 10:23:7 - PFRO Error: \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\New\PrintConfig.dll, \??\C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\PrintConfig.dll, 0xc000003a
5/21/2017 10:23:7 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
5/21/2017 10:23:8 - 5 Successful PFRO operations

6/7/2017 5:8:16 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
6/7/2017 5:8:16 - 4 Successful PFRO operations

6/23/2017 9:38:40 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
6/23/2017 9:38:41 - 3 Successful PFRO operations

6/24/2017 12:53:6 - PFRO Error: \??\C:\WINDOWS\System32\G2AC_CredentialProvider.dll, |delete operation|, 0xc0000034
6/24/2017 12:53:6 - PFRO Error: \??\C:\ProgramData\WebEx\WebEx\1525, |delete operation|, 0xc0000034
6/24/2017 12:53:6 - PFRO Error: \??\C:\PROGRAMDATA\WEBEX\WEBEX\1425, |delete operation|, 0xc0000034
6/24/2017 12:53:6 - PFRO Error: \??\C:\PROGRAMDATA\WEBEX\WEBEX\T30_TC, |delete operation|, 0xc0000034
6/24/2017 12:53:6 - PFRO Error: \??\C:\PROGRAMDATA\WEBEX\WEBEX\T31_UMC, |delete operation|, 0xc0000034
6/24/2017 12:53:6 - 7 Successful PFRO operations

6/26/2017 7:52:52 - PFRO Error: \??\C:\Users\AIRWOR~1\AppData\Local\Temp\eset.temp, |delete operation|, 0xc0000101
6/26/2017 7:52:52 - 277 Successful PFRO operations

6/27/2017 14:42:40 - PFRO Error: \??\C:\Users\AIRWORX 2\AppData\Local\ESET\ESETOnlineScanner\Quarantine, |delete operation|, 0xc0000034
6/27/2017 14:42:40 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}\59.0.3071.115_59.0.3071.109_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:40 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109\59.0.3071.109_58.0.3029.110_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}\59.0.3071.115_59.0.3071.109_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{AE98704E-191E-4DAE-A299-9517E41B1043}\59.0.3071.115_59.0.3071.109_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{AE98704E-191E-4DAE-A299-9517E41B1043}, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109\59.0.3071.109_58.0.3029.110_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}\59.0.3071.115_59.0.3071.109_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{8A44E8A8-9DA5-47BA-BC68-73485DDD0AAB}, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{AE98704E-191E-4DAE-A299-9517E41B1043}\59.0.3071.115_59.0.3071.109_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Install\{AE98704E-191E-4DAE-A299-9517E41B1043}, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109\59.0.3071.109_58.0.3029.110_chrome_updater.exe, |delete operation|, 0xc000003a
6/27/2017 14:42:41 - PFRO Error: \??\C:\Program Files (x86)\Google\Update\Download\{8A69D345-D564-463C-AFF1-A69D9E530F96}\59.0.3071.109, |delete operation|, 0xc0000034
6/27/2017 14:42:41 - 8 Successful PFRO operations

6/29/2017 10:45:17 - PFRO Error: \??\C:\ProgramData\bomgar-scc-0x59552012\remove.exe, |delete operation|, 0xc0000034
6/29/2017 10:45:17 - PFRO Error: \??\C:\ProgramData\bomgar-scc-0x59552012\remove.exe, |delete operation|, 0xc000003a
6/29/2017 10:45:17 - 2 Successful PFRO operations

6/30/2017 6:2:18 - PFRO Error: \??\C:\Program Files (x86)\Dropbox\OldBinaries, |delete operation|, 0xc0000101
6/30/2017 6:2:18 - 0 Successful PFRO operations

7/12/2017 7:55:42 - PFRO Error: \??\C:\Windows\Temp\services.exe.mui, |delete operation|, 0xc0000034
7/12/2017 7:55:42 - 0 Successful PFRO operations


  • 0

#36
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Another log file same location named  setupact

 

[05/15/2017 13:09.28.475] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[05/15/2017 13:09.28.615] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[05/15/2017 13:09.28.681] WudfCoInstaller: Configuring UMDF Service WpdFs.

[05/15/2017 13:09.28.752] WudfCoInstaller: ImpersonationLevel set to 2

[05/15/2017 13:09.28.832] WudfCoInstaller: Using "Win7" service configuration

[05/15/2017 13:09.28.952] WudfCoInstaller: Service WudfSvc is already running.

[05/15/2017 13:09.29.085] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/15/2017 13:09.29.338] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

[05/25/2017 09:08.14.976] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[05/25/2017 09:08.15.025] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[05/25/2017 09:08.15.044] WudfCoInstaller: Configuring UMDF Service WpdFs.

[05/25/2017 09:08.15.067] WudfCoInstaller: ImpersonationLevel set to 2

[05/25/2017 09:08.15.085] WudfCoInstaller: Using "Win7" service configuration

[05/25/2017 09:08.15.109] WudfCoInstaller: Service WudfSvc is already running.

[05/25/2017 09:08.15.128] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/25/2017 09:08.15.417] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

WdfCoInstaller: [05/26/2017 02:15.18.285] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/26/2017 02:15.18.313] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/26/2017 02:15.18.332] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/26/2017 02:15.18.517] DIF_INSTALLDEVICE: Post-Processing

[05/26/2017 02:15.48.789] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[05/26/2017 02:15.48.834] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem39.inf.

[05/26/2017 02:15.48.856] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[05/26/2017 02:15.48.874] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/26/2017 02:15.48.897] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/26/2017 02:15.48.916] WudfCoInstaller: ImpersonationLevel set to 2

[05/26/2017 02:15.48.938] WudfCoInstaller: Using "Win7" service configuration

[05/26/2017 02:15.48.957] WudfCoInstaller: Service WudfSvc is already running.

[05/26/2017 02:15.49.018] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/26/2017 02:15.49.724] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [05/26/2017 02:20.53.523] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/26/2017 02:20.53.671] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/26/2017 02:20.53.704] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/26/2017 02:20.53.801] DIF_INSTALLDEVICE: Post-Processing

WdfCoInstaller: [05/26/2017 05:21.01.101] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/26/2017 05:21.01.138] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/26/2017 05:21.01.162] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/26/2017 05:21.01.328] DIF_INSTALLDEVICE: Post-Processing

[05/30/2017 18:10.43.535] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[05/30/2017 18:10.43.652] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[05/30/2017 18:10.43.728] WudfCoInstaller: Configuring UMDF Service WpdFs.

[05/30/2017 18:10.43.802] WudfCoInstaller: ImpersonationLevel set to 2

[05/30/2017 18:10.43.848] WudfCoInstaller: Using "Win7" service configuration

[05/30/2017 18:10.43.918] WudfCoInstaller: Service WudfSvc is already running.

[05/30/2017 18:10.43.965] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/30/2017 18:10.46.376] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

[05/31/2017 07:46.16.799] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[05/31/2017 07:46.16.936] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem39.inf.

[05/31/2017 07:46.16.993] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[05/31/2017 07:46.17.067] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 07:46.17.137] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 07:46.17.184] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 07:46.17.253] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 07:46.17.301] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 07:46.17.354] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 07:46.18.707] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [05/31/2017 07:46.22.426] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/31/2017 07:46.22.530] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/31/2017 07:46.22.624] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/31/2017 07:46.23.009] DIF_INSTALLDEVICE: Post-Processing

[05/31/2017 09:34.05.215] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[05/31/2017 09:34.05.317] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:34.05.348] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:34.05.371] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:34.05.387] WudfCoInstaller: KernelModeClientPolicy set to 1

[05/31/2017 09:34.05.401] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:34.05.432] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:34.05.468] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:34.55.979] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[05/31/2017 09:36.02.024] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[05/31/2017 09:36.02.067] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:36.02.081] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:36.02.095] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:36.02.132] WudfCoInstaller: KernelModeClientPolicy set to 1

[05/31/2017 09:36.02.165] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:36.02.178] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:36.02.190] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:36.57.602] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[05/31/2017 09:37.50.124] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[05/31/2017 09:37.50.212] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:37.50.251] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:37.50.290] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:37.50.325] WudfCoInstaller: KernelModeClientPolicy set to 1

[05/31/2017 09:37.50.377] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:37.50.421] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:37.50.446] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:37.50.886] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[05/31/2017 09:38.53.960] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[05/31/2017 09:38.53.998] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:38.54.023] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:38.54.047] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:38.54.065] WudfCoInstaller: KernelModeClientPolicy set to 1

[05/31/2017 09:38.54.080] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:38.54.107] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:38.54.140] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:39.49.358] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [05/31/2017 09:53.37.588] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/31/2017 09:53.37.640] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/31/2017 09:53.37.675] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/31/2017 09:53.37.812] DIF_INSTALLDEVICE: Post-Processing

[05/31/2017 09:53.40.984] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[05/31/2017 09:53.41.030] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:53.41.045] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:53.41.061] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:53.41.078] WudfCoInstaller: KernelModeClientPolicy set to 1

[05/31/2017 09:53.41.094] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:53.41.120] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:53.41.144] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:53.41.479] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [05/31/2017 09:53.54.994] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/31/2017 09:53.55.032] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/31/2017 09:53.55.055] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/31/2017 09:53.55.760] DIF_INSTALLDEVICE: Post-Processing

[05/31/2017 09:54.07.115] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[05/31/2017 09:54.07.148] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem73.inf.

[05/31/2017 09:54.07.171] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[05/31/2017 09:54.07.197] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:54.07.221] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:54.07.239] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:54.07.262] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:54.07.280] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:54.07.304] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:54.07.517] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[05/31/2017 09:54.10.854] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[05/31/2017 09:54.10.913] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem73.inf.

[05/31/2017 09:54.10.931] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[05/31/2017 09:54.10.972] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[05/31/2017 09:54.11.020] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[05/31/2017 09:54.11.046] WudfCoInstaller: ImpersonationLevel set to 2

[05/31/2017 09:54.11.064] WudfCoInstaller: Using "Win7" service configuration

[05/31/2017 09:54.11.088] WudfCoInstaller: Service WudfSvc is already running.

[05/31/2017 09:54.11.106] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[05/31/2017 09:54.13.673] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [05/31/2017 09:55.07.548] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/31/2017 09:55.07.596] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/31/2017 09:55.07.620] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/31/2017 09:55.07.711] DIF_INSTALLDEVICE: Post-Processing

WdfCoInstaller: [05/31/2017 09:57.59.666] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [05/31/2017 09:57.59.742] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[05/31/2017 09:57.59.787] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [05/31/2017 09:57.59.967] DIF_INSTALLDEVICE: Post-Processing

[06/16/2017 08:45.50.353] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[06/16/2017 08:45.50.493] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem73.inf.

[06/16/2017 08:45.50.544] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[06/16/2017 08:45.50.580] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/16/2017 08:45.50.610] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/16/2017 08:45.50.681] WudfCoInstaller: ImpersonationLevel set to 2

[06/16/2017 08:45.50.723] WudfCoInstaller: Using "Win7" service configuration

[06/16/2017 08:45.50.757] WudfCoInstaller: Service WudfSvc is already running.

[06/16/2017 08:45.50.817] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/16/2017 08:45.54.300] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/19/2017 12:20.03.699] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[06/19/2017 12:20.03.756] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[06/19/2017 12:20.03.786] WudfCoInstaller: Configuring UMDF Service WpdFs.

[06/19/2017 12:20.03.828] WudfCoInstaller: ImpersonationLevel set to 2

[06/19/2017 12:20.03.844] WudfCoInstaller: Using "Win7" service configuration

[06/19/2017 12:20.03.864] WudfCoInstaller: Service WudfSvc is already running.

[06/19/2017 12:20.03.877] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/19/2017 12:20.04.165] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

[06/20/2017 02:24.06.008] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[06/20/2017 02:24.06.053] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem73.inf.

[06/20/2017 02:24.06.072] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[06/20/2017 02:24.06.092] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/20/2017 02:24.06.114] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/20/2017 02:24.06.134] WudfCoInstaller: ImpersonationLevel set to 2

[06/20/2017 02:24.06.155] WudfCoInstaller: Using "Win7" service configuration

[06/20/2017 02:24.06.176] WudfCoInstaller: Service WudfSvc is already running.

[06/20/2017 02:24.06.197] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/20/2017 02:24.06.491] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/20/2017 03:32.56.273] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/20/2017 03:32.56.310] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/20/2017 03:32.56.330] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/20/2017 03:32.56.351] WudfCoInstaller: ImpersonationLevel set to 2

[06/20/2017 03:32.56.371] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/20/2017 03:32.56.393] WudfCoInstaller: Using "Win7" service configuration

[06/20/2017 03:32.56.414] WudfCoInstaller: Service WudfSvc is already running.

[06/20/2017 03:32.56.435] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/20/2017 03:32.59.398] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/20/2017 03:36.01.176] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/20/2017 03:36.01.271] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/20/2017 03:36.01.309] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/20/2017 03:36.01.330] WudfCoInstaller: ImpersonationLevel set to 2

[06/20/2017 03:36.01.351] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/20/2017 03:36.01.388] WudfCoInstaller: Using "Win7" service configuration

[06/20/2017 03:36.01.410] WudfCoInstaller: Service WudfSvc is already running.

[06/20/2017 03:36.01.430] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/20/2017 03:36.02.984] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [06/21/2017 06:09.18.631] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [06/21/2017 06:09.18.772] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[06/21/2017 06:09.18.862] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [06/21/2017 06:09.19.082] DIF_INSTALLDEVICE: Post-Processing

[06/21/2017 06:09.48.869] WudfCoInstaller: ReadWdfSection: Checking WdfSection [ssud.Install.Wdf]

[06/21/2017 06:09.48.920] WudfCoInstaller: Imported INF file wpdmtp.inf according to Include directive on line 0 of C:\WINDOWS\INF\oem73.inf.

[06/21/2017 06:09.48.939] WudfCoInstaller: Imported section [WPD.MTP.Wdf] according to section [ssud.Install.Wdf] line 1, Needs directive.

[06/21/2017 06:09.48.959] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/21/2017 06:09.48.981] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/21/2017 06:09.49.001] WudfCoInstaller: ImpersonationLevel set to 2

[06/21/2017 06:09.49.022] WudfCoInstaller: Using "Win7" service configuration

[06/21/2017 06:09.49.043] WudfCoInstaller: Service WudfSvc is already running.

[06/21/2017 06:09.49.065] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/21/2017 06:09.49.400] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

WdfCoInstaller: [06/21/2017 06:09.53.207] DIF_INSTALLDEVICE: Pre-Processing

WdfCoInstaller: [06/21/2017 06:09.53.244] ReadComponents:  WdfSection for Driver Service WINUSB using KMDF lib version Major 0x1, minor 0x7

[06/21/2017 06:09.53.266] WinusbUpdate: No update found for this OS, but OS is supported - returning NO_ERROR.

WdfCoInstaller: [06/21/2017 06:09.53.366] DIF_INSTALLDEVICE: Post-Processing

[06/29/2017 09:58.59.962] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[06/29/2017 09:59.00.121] WudfCoInstaller: Configuring UMDF Service WpdFs.

[06/29/2017 09:59.00.193] WudfCoInstaller: ImpersonationLevel set to 2

[06/29/2017 09:59.00.224] WudfCoInstaller: Using "Win7" service configuration

[06/29/2017 09:59.00.290] WudfCoInstaller: Service WudfSvc is already running.

[06/29/2017 09:59.00.330] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/29/2017 09:59.09.218] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

[06/29/2017 14:21.07.190] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[06/29/2017 14:21.07.335] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[06/29/2017 14:21.07.371] WudfCoInstaller: Configuring UMDF Service WpdFs.

[06/29/2017 14:21.07.421] WudfCoInstaller: ImpersonationLevel set to 2

[06/29/2017 14:21.07.476] WudfCoInstaller: Using "Win7" service configuration

[06/29/2017 14:21.07.581] WudfCoInstaller: Service WudfSvc is already running.

[06/29/2017 14:21.07.646] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/29/2017 14:21.08.025] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.

[06/30/2017 10:28.00.504] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.00.543] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.00.596] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.00.649] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.00.708] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.00.743] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.00.808] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.00.843] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.01.057] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:28.02.859] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.03.113] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.03.135] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.03.157] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.03.177] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.03.198] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.03.222] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.03.240] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.03.374] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:28.14.624] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.14.666] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.14.695] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.14.716] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.14.734] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.14.757] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.14.776] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.14.816] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.14.937] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:28.17.502] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.17.534] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.17.558] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.17.576] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.17.599] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.17.617] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.17.642] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.17.659] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.17.903] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:28.21.164] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.21.208] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.21.226] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.21.250] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.21.268] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.21.291] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.21.310] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.21.333] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.21.497] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:28.23.157] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:28.23.204] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:28.23.226] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:28.23.250] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:28.23.268] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:28.23.291] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:28.23.310] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:28.23.349] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:28.24.242] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[06/30/2017 10:29.13.890] WudfCoInstaller: ReadWdfSection: Checking WdfSection [MTP.NT.Wdf]

[06/30/2017 10:29.13.938] WudfCoInstaller: UMDF Service WpdMtpDriver is already installed - removing existing settings in preparation for setting new ones.

[06/30/2017 10:29.13.956] WudfCoInstaller: Configuring UMDF Service WpdMtpDriver.

[06/30/2017 10:29.13.980] WudfCoInstaller: ImpersonationLevel set to 2

[06/30/2017 10:29.13.997] WudfCoInstaller: KernelModeClientPolicy set to 1

[06/30/2017 10:29.14.021] WudfCoInstaller: Using "Win7" service configuration

[06/30/2017 10:29.14.040] WudfCoInstaller: Service WudfSvc is already running.

[06/30/2017 10:29.14.063] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[06/30/2017 10:29.14.303] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdMtpDr_01_11_00.Wdf.

[07/11/2017 12:04.10.734] WudfCoInstaller: ReadWdfSection: Checking WdfSection [Basic_Install.Wdf]

[07/11/2017 12:04.10.953] WudfCoInstaller: UMDF Service WpdFs is already installed - removing existing settings in preparation for setting new ones.

[07/11/2017 12:04.11.000] WudfCoInstaller: Configuring UMDF Service WpdFs.

[07/11/2017 12:04.11.078] WudfCoInstaller: ImpersonationLevel set to 2

[07/11/2017 12:04.11.141] WudfCoInstaller: Using "Win7" service configuration

[07/11/2017 12:04.11.375] WudfCoInstaller: Service WudfSvc is already running.

[07/11/2017 12:04.11.437] WudfCoInstaller: Final status: error(0) The operation completed successfully.

[07/11/2017 12:04.12.594] WudfCoInstaller: Created marker file C:\WINDOWS\system32\drivers\Msft_User_WpdFs_01_11_00.Wdf.


  • 0

#37
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Chrome installer log I found, from right around time my issues started, located in C:\Windows\Temp

 

[0515/202748.221:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome
[0515/202748.221:VERBOSE1:setup_main.cc(1349)] system install is 1
[0515/202748.221:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0515/202748.221:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0515/202748.252:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0515/202748.346:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0515/202748.346:VERBOSE1:setup_main.cc(663)] Entered background processing mode.
[0515/202748.862:VERBOSE1:setup_main.cc(667)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0515/202749.377:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0515/202750.237:VERBOSE1:setup_main.cc(1099)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z
[0515/202750.752:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z
[0515/202751.268:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/202922.825:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\chrome.7z
[0515/202923.372:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/203307.101:VERBOSE1:setup_main.cc(1158)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/203307.867:VERBOSE1:setup_util.cc(291)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin
[0515/203308.023:VERBOSE1:setup_util.cc(302)] directory found: 58.0.3029.110
[0515/203308.023:VERBOSE1:setup_main.cc(1169)] version to install: 58.0.3029.110
[0515/203308.023:VERBOSE1:install.cc(324)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin
[0515/203308.039:VERBOSE1:install_worker.cc(273)] Adding unregistration items for DelegateExecute verb handler.
[0515/203308.039:VERBOSE1:install_worker.cc(785)] Adding unregistration items for per-user Metro keys.
[0515/203308.039:VERBOSE1:install_worker.cc(809)] Adding registration items for Active Setup.
[0515/203308.039:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0515/203308.352:VERBOSE1:copy_tree_work_item.cc(62)] Copied source file C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\chrome.exe to alternative path C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_1232_24242\chrome.VisualElementsManifest.xml
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\58.0.3029.110 to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0515/203308.571:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe
[0515/203308.617:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe
[0515/203308.617:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrome.7z
[0515/203309.133:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Google\Chrome\Metro
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Google\Chrome\Metro
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0515/203309.899:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0515/203310.289:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0515/203310.618:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0515/203311.102:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list InUseUpdateWorkItemList
[0515/203311.102:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0515/203311.102:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list InUseUpdateWorkItemList
[0515/203311.102:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0515/203311.102:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list RegularUpdateWorkItemList
[0515/203311.102:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0515/203311.102:VERBOSE1:install.cc(234)] Version updated to 58.0.3029.110 while running 58.0.3029.96
[0515/203311.102:VERBOSE1:installer_state.cc(282)] ap: -full
[0515/203311.102:VERBOSE1:install.cc(111)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.414:VERBOSE1:install.cc(111)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.446:WARNING:install.cc(109)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.446:VERBOSE1:install.cc(111)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.477:VERBOSE1:install.cc(131)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0515/203311.993:VERBOSE1:setup_util.cc(691)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0515/203312.149:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0515/203312.149:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0515/203312.462:VERBOSE1:install.cc(450)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0515/203312.462:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0515/203312.462:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0515/203312.477:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\ChromeExt
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\.crx
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\ChromeExt
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\.crx
[0515/203312.477:VERBOSE1:product.cc(115)] LaunchUserExperiment status: 30 product: Google Chrome system_level: 1
[0515/203312.477:VERBOSE1:user_experiment.cc(437)] Toast experiment is disabled.
[0515/203312.477:VERBOSE1:setup_main.cc(1305)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0515/203312.477:VERBOSE1:google_update_settings.cc(474)] Removed incremental installer failure key; switching to channel:
[0515/203312.477:VERBOSE1:setup_main.cc(1507)] Installation complete, returning: 0
[0515/203312.774:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170515203312.pma
[0521/092347.578:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --rename-chrome-exe --system-level --verbose-logging
[0521/092347.592:VERBOSE1:setup_main.cc(1349)] system install is 1
[0521/092347.594:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.595:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0521/092347.628:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0521/092347.631:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.632:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0521/092347.634:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Application\chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
[0521/092347.635:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0521/092347.635:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0521/092347.637:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0521/092347.637:VERBOSE1:install.cc(598)] Launching ""C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --delete-old-versions --system-level --verbose-logging" to delete old versions.
[0521/092347.648:VERBOSE1:setup_main.cc(472)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0521/092347.650:WARNING:self_cleaning_temp_dir.cc(84)] Failed to delete temporary directory C:\Program Files (x86)\Google\Chrome\Temp. Scheduling for deletion at reboot.
[0521/092347.661:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --delete-old-versions --system-level --verbose-logging
[0521/092347.661:VERBOSE1:setup_main.cc(1349)] system install is 1
[0521/092347.661:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8768_32057\old_chrome.exe
[0521/092347.662:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.662:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0521/092347.662:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8768_32057
[0521/092347.662:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp
[0521/092347.685:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0521/092347.686:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.722:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170521092347.pma
[0521/092402.778:WARNING:delete_old_versions.cc(92)] Attempting to delete stray directory C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.96
[0521/092403.419:VERBOSE1:setup_main.cc(387)] Successfully deleted all old files from --delete-old-versions process.
[0521/092403.482:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170521092403.pma
[0624/083032.355:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program" --update-setup-exe="C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z" --new-setup-exe="C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe" --verbose-logging --do-not-launch-chrome Files "(x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe"
[0624/083032.385:VERBOSE1:setup_main.cc(1349)] system install is 1
[0624/083032.387:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083032.388:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0624/083032.646:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0624/083032.648:VERBOSE1:setup_main.cc(832)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z
[0624/083032.648:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z
[0624/083032.648:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\WINDOWS\TEMP\scoped_dir984_712
[0624/083035.111:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170624083034.pma
[0624/083036.315:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z" --previous-version=58.0.3029.110 --verbose-logging --do-not-launch-chrome
[0624/083036.355:VERBOSE1:setup_main.cc(1348)] system install is 1
[0624/083036.356:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083036.356:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0624/083036.491:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0624/083036.493:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083036.494:VERBOSE1:setup_main.cc(662)] Entered background processing mode.
[0624/083036.494:VERBOSE1:setup_main.cc(666)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0624/083036.495:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0624/083036.505:VERBOSE1:setup_main.cc(1098)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z
[0624/083036.517:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z
[0624/083036.517:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083401.776:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\chrome.7z
[0624/083401.777:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083610.542:VERBOSE1:setup_main.cc(1157)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083610.543:VERBOSE1:setup_util.cc(321)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin
[0624/083610.544:VERBOSE1:setup_util.cc(332)] directory found: 59.0.3071.109
[0624/083610.544:VERBOSE1:setup_main.cc(1168)] version to install: 59.0.3071.109
[0624/083610.622:VERBOSE1:install.cc(325)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin
[0624/083610.636:VERBOSE1:install_worker.cc(787)] Adding unregistration items for per-user Metro keys.
[0624/083610.636:VERBOSE1:install_worker.cc(813)] Adding registration items for Active Setup.
[0624/083610.637:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0624/083610.637:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0624/083610.637:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0624/083610.638:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0624/083610.701:VERBOSE1:copy_tree_work_item.cc(62)] Copied source file C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\chrome.exe to alternative path C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe
[0624/083610.711:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_6020_17361\chrome.VisualElementsManifest.xml
[0624/083610.712:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0624/083610.714:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\59.0.3071.109 to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109
[0624/083610.714:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer
[0624/083610.715:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer
[0624/083610.716:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0624/083610.772:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\setup.exe
[0624/083610.806:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\chrmstp.exe
[0624/083610.808:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\chrome.7z
[0624/083610.809:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0624/083610.810:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0624/083610.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0624/083611.100:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0624/083611.101:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0624/083611.251:ERROR:install_worker.cc(148)] Failed creating a firewall rules. Continuing with install.
[0624/083611.252:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0624/083611.252:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0624/083611.252:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0624/083611.253:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list InUseUpdateWorkItemList
[0624/083611.253:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0624/083611.253:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list InUseUpdateWorkItemList
[0624/083611.254:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0624/083611.254:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list RegularUpdateWorkItemList
[0624/083611.254:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0624/083611.255:VERBOSE1:install.cc(235)] Version updated to 59.0.3071.109 while running 58.0.3029.110
[0624/083611.256:VERBOSE1:installer_state.cc(283)] ap: -full
[0624/083611.256:VERBOSE1:install.cc(112)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.325:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.326:VERBOSE1:install.cc(112)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.327:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.328:VERBOSE1:install.cc(112)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.527:VERBOSE1:install.cc(132)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0624/083611.527:VERBOSE1:setup_util.cc(721)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0624/083611.528:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0624/083611.530:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0624/083612.034:VERBOSE1:install.cc(451)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0624/083612.538:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0624/083613.055:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0624/083613.566:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0624/083614.089:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0624/083614.594:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0624/083615.098:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0624/083615.602:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0624/083616.107:VERBOSE1:product.cc(119)] LaunchUserExperiment status: 30 product: Google Chrome system_level: 1
[0624/083616.611:VERBOSE1:user_experiment.cc(437)] Toast experiment is disabled.
[0624/083617.115:VERBOSE1:setup_main.cc(1304)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0624/083617.629:VERBOSE1:google_update_settings.cc(475)] Removed incremental installer failure key; switching to channel:
[0624/083618.290:VERBOSE1:setup_main.cc(1506)] Installation complete, returning: 0
[0624/083619.170:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170624083619.pma
[0626/192841.405:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\Program" --update-setup-exe="C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z" --new-setup-exe="C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe" --verbose-logging --do-not-launch-chrome Files "(x86)\Google\Chrome\Application\59.0.3071.109\Installer\setup.exe"
[0626/192841.431:VERBOSE1:setup_main.cc(1348)] system install is 1
[0626/192841.434:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/192841.435:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0626/192939.613:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0626/192939.627:VERBOSE1:setup_main.cc(831)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z
[0626/192939.627:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z
[0626/192939.627:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\WINDOWS\TEMP\scoped_dir6980_30351
[0626/192940.371:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170626192939.pma
[0626/193038.499:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z" --previous-version=59.0.3071.109 --verbose-logging --do-not-launch-chrome
[0626/193038.531:VERBOSE1:setup_main.cc(1348)] system install is 1
[0626/193038.533:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/193038.533:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0626/193136.633:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0626/193136.635:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/193136.636:VERBOSE1:setup_main.cc(662)] Entered background processing mode.
[0626/193136.636:VERBOSE1:setup_main.cc(666)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0626/193136.637:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0626/193136.638:VERBOSE1:setup_main.cc(1098)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z
[0626/193136.662:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z
[0626/193136.663:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193237.373:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\chrome.7z
[0626/193237.374:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193250.735:VERBOSE1:setup_main.cc(1157)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193250.735:VERBOSE1:setup_util.cc(321)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin
[0626/193250.736:VERBOSE1:setup_util.cc(332)] directory found: 59.0.3071.115
[0626/193250.736:VERBOSE1:setup_main.cc(1168)] version to install: 59.0.3071.115
[0626/193251.252:VERBOSE1:install.cc(325)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin
[0626/193251.419:VERBOSE1:install_worker.cc(787)] Adding unregistration items for per-user Metro keys.
[0626/193251.587:VERBOSE1:install_worker.cc(813)] Adding registration items for Active Setup.
[0626/193251.588:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0626/193251.588:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0626/193251.589:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0626/193251.590:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0626/193251.628:VERBOSE1:copy_tree_work_item.cc(85)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_3892_3436\chrome.exe
[0626/193252.752:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0626/193252.754:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_3892_12452\chrome.VisualElementsManifest.xml
[0626/193252.755:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0626/193252.756:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\59.0.3071.115 to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115
[0626/193252.757:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer
[0626/193252.757:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer
[0626/193252.758:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0626/193252.877:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\setup.exe
[0626/193253.721:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe
[0626/193253.724:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrome.7z
[0626/193253.727:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0626/193253.728:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0626/193351.810:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0626/193351.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0626/193351.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0626/193351.872:ERROR:install_worker.cc(148)] Failed creating a firewall rules. Continuing with install.
[0626/193351.873:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0626/193351.873:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0626/193351.873:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list InUseUpdateWorkItemList
[0626/193351.874:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0626/193351.874:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0626/193351.874:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list RegularUpdateWorkItemList
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: opv does not exist.
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cmd does not exist.
[0626/193351.876:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list RegularUpdateWorkItemList
[0626/193351.876:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0626/193351.876:VERBOSE1:install.cc(239)] Version updated to 59.0.3071.115
[0626/193351.878:VERBOSE1:installer_state.cc(283)] ap: -full
[0626/193351.879:VERBOSE1:install.cc(112)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.881:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.882:VERBOSE1:install.cc(112)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.883:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.901:VERBOSE1:install.cc(112)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193352.030:VERBOSE1:install.cc(132)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0626/193352.054:VERBOSE1:setup_util.cc(721)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0626/193352.054:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0626/193842.460:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0626/193842.461:VERBOSE1:install.cc(451)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0626/193842.461:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0626/193842.466:WARNING:delete_old_versions.cc(92)] Attempting to delete stray directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109
[0626/193842.505:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0626/193842.506:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0626/193842.506:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0626/193842.507:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0626/193842.508:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0626/193842.508:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0626/193842.508:VERBOSE1:product.cc(119)] LaunchUserExperiment status: 2 product: Google Chrome system_level: 1
[0626/193842.522:VERBOSE1:user_experiment.cc(244)] LaunchSetupAsConsoleUser launching "C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\setup.exe" --system-level-toast --system-level --verbose-logging --toast-results-key=740
[0626/193940.705:VERBOSE1:user_experiment.cc(247)] LaunchSetupAsConsoleUser   result: 1
[0626/193940.706:VERBOSE1:setup_main.cc(1304)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0626/193940.761:VERBOSE1:google_update_settings.cc(475)] Removed incremental installer failure key; switching to channel:
[0626/193940.773:VERBOSE1:setup_main.cc(1506)] Installation complete, returning: 0
[0626/193940.835:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170626193940.pma
 


  • 0

#38
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

Just take a screenshot of the Kaspersky screen showing what it found if it shows any viruses or malware.  We don't care about the Other Issues.  Use the snipping tool

 

https://www.tekrevue...-snipping-tool/

 

Save the file as a jpg then

 

First click on More Reply Options

Then scroll down to where you see
Choose File and click on it.  Point it at the file and hit Open.
Now click on Attach this file.
 
The first log is something to do with PFRO (Pending File Rename Operations) the second with a driver install.  I think you plugged in a USB drive.  Not sure why Windows is generating the logs but both are harmless.   

  • 0

#39
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Ok, Here are the requested screen shots, as well as a few others, that show you, what I'm talking about when I mention different users that I didn't create.Capture6.JPG

Capture.JPG

Capture2.JPG

Capture3.JPG

Capture4.JPG

Capture5.JPG

Capture9.JPG

Capture10.JPG

Capture11.JPG

 

 


  • 0

#40
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Ok, Here are the requested screen shots, as well as a few others, that show you, what I'm talking about when I mention different users that I didn't create.Capture6.JPG

Capture.JPG

Capture2.JPG

Capture3.JPG

Capture4.JPG

Capture5.JPG

Capture9.JPG

Capture10.JPG

Capture11.JPG

 

 


  • 0

Advertisements


#41
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Ok, so I decided to start back, with step one, to see where we are at. 

 

 

Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 15-07-2017
Ran by AIRWORX 2 (administrator) on AIRWORX2-PC (17-07-2017 13:28:26)
Running from C:\Users\AIRWORX 2\Desktop\Cleanup apps
Loaded Profiles: AIRWORX 2 & Administrator (Available Profiles: AIRWORX 2 & AirworxAZ & Administrator)
Platform: Windows 10 Home Version 1703 (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: IE)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo...very-scan-tool/
 
==================== Processes (Whitelisted) =================
 
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
 
(ESET) C:\Program Files\ESET\ESET Security\ekrn.exe
(AMD) C:\Windows\System32\atiesrxx.exe
(Dropbox, Inc.) C:\Windows\System32\DbxSvc.exe
(Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
(Seagate) C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedul2.exe
(Adobe Systems, Incorporated) C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe
(Nuance Communications, Inc.) C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe
() C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe
() C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(AMD) C:\Windows\System32\atieclxx.exe
(IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe
(ESET) C:\Program Files\ESET\ESET Security\egui.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCuiL.exe
(Fitbit, Inc.) C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe
(Shutterfly, Inc.) C:\Program Files (x86)\Shutterfly Uploader\ThisLife.Uploader.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCtrlCntr.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Dropbox, Inc.) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\WDAppManager.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\ControlCenter4\BrCcUxSys.exe
(Western Digital Technologies, Inc.) C:\Program Files (x86)\Western Digital\WD App Manager\Plugins\WD Sync\App\WDSyncService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41225.0_x64__8wekyb3d8bbwe\HxCalendarAppImm.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41225.0_x64__8wekyb3d8bbwe\HxTsr.exe
(Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41225.0_x64__8wekyb3d8bbwe\HxOutlook.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.15063.410_none_9e914f9d2d85dacb\TiWorker.exe
(Microsoft Corporation) C:\Windows\HelpPane.exe
(Microsoft Corporation) C:\Windows\System32\SystemSettingsAdminFlows.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
() C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x64__8wekyb3d8bbwe\Calculator.exe
(Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
(HP Inc.) C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Users\AIRWORX 2\Downloads\msert (2).exe
(Microsoft Corporation) C:\Users\AIRWORX 2\Downloads\msert (2).exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
(Microsoft Corporation) C:\Windows\System32\smartscreen.exe
 
==================== Registry (Whitelisted) ====================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [SecurityHealth] => C:\Program Files\Windows Defender\MSASCuiL.exe [629152 2017-03-18] (Microsoft Corporation)
HKLM\...\Run: [Seagate Scheduler2 Service] => C:\Program Files (x86)\Common Files\Seagate\Schedule2\schedhlp.exe [395152 2011-06-30] (Seagate)
HKLM\...\Run: [BeatsOSDApp] => C:\Program Files\IDT\WDM\beats64.exe [41664 2013-11-20] (Hewlett-Packard )
HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1703424 2013-11-20] (IDT, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [767176 2015-11-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\isuspm.exe [2068856 2011-10-12] (Flexera Software LLC.)
HKLM-x32\...\Run: [PaperPort PTD] => C:\Program Files (x86)\Nuance\PaperPort\pptd40nt.exe [36168 2013-05-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [IndexSearch] => C:\Program Files (x86)\Nuance\PaperPort\IndexSearch.exe [18248 2013-05-14] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PPort14reminder] => "C:\Program Files (x86)\Nuance\PaperPort\Ereg\Ereg.exe" -r "C:\ProgramData\ScanSoft\PaperPort\14\Config\Ereg\Ereg.ini"
HKLM-x32\...\Run: [PDFProHook] => C:\Program Files (x86)\Nuance\PDFViewer\pdfpro7hook.exe [641864 2013-03-20] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDFCreHook] => C:\Program Files (x86)\Nuance\PDFCreate\pdfcreate7hook.exe [605512 2013-03-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [PDF7 Registry Controller] => C:\Program Files (x86)\Nuance\PDFCreate\RegistryController.exe [140616 2013-03-26] (Nuance Communications, Inc.)
HKLM-x32\...\Run: [Adobe Photo Downloader] => C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\apdproxy.exe [57344 2005-09-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [673616 2009-04-07] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [ControlCenter4] => C:\Program Files (x86)\ControlCenter4\BrCcBoot.exe [143360 2012-09-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [BrStsMon00] => C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [3076096 2012-06-06] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Dropbox] => C:\Program Files (x86)\Dropbox\Client\Dropbox.exe [3486520 2017-07-12] (Dropbox, Inc.)
HKLM-x32\...\Run: [WDAppManager] => C:\Program Files (x86)\Western Digital\WD App Manager\AppManagerLauncher.exe [21384 2016-04-15] (Western Digital Technologies, Inc.)
HKLM-x32\...\Run: [DiscWizardMonitor.exe] => C:\Program Files (x86)\Seagate\DiscWizard\DiscWizardMonitor.exe [2638152 2011-06-30] (Seagate)
HKLM-x32\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
HKLM-x32\...\Run: [Vault Explorer Cache Watcher] => C:\Program Files (x86)\Cox\Drag and Drop Backup\vewatch.exe [17408 2013-02-21] (DigiData Corp.) <==== ATTENTION
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM\...\Policies\Explorer: [0] 0
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [Fitbit Connect] => C:\Program Files (x86)\Fitbit Connect\Fitbit Connect.exe [4567720 2015-10-28] (Fitbit, Inc.)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [SmartSwitchPDLR.exe] => C:\Program Files (x86)\Samsung\Smart Switch PC\SmartSwitchPDLR.exe [1037984 2017-05-20] (Samsung)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [KSS] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Run: [Kaspersky Software Updater] => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab)
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\RunOnce: [Uninstall 17.3.6743.1212\amd64] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\RunOnce: [Uninstall 17.3.6743.1212] => C:\WINDOWS\system32\cmd.exe /q /c rmdir /s /q "C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212"
HKU\S-1-5-21-2671885098-678752524-1400920573-500\...\RunOnce: [WAB Migrate] => C:\Program Files\Windows Mail\wab.exe [517120 2017-03-18] (Microsoft Corporation)
Startup: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk [2015-06-18]
ShortcutTarget: OneNote 2010 Screen Clipper and Launcher.lnk -> C:\Program Files (x86)\Microsoft Office\Office14\ONENOTEM.EXE (Microsoft Corporation)
Startup: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Verizon Wireless Software Utility Application for Android – Samsung.lnk [2017-02-20]
ShortcutTarget: Verizon Wireless Software Utility Application for Android – Samsung.lnk -> C:\Users\AIRWORX 2\AppData\Roaming\VERIZON\UA_ar\UA.exe (SAMSUNG Electornics Co., Ltd.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Cox Cloud Drive.lnk [2017-04-21]
ShortcutTarget: Cox Cloud Drive.lnk -> C:\Program Files (x86)\Cox Secure Online Backup for Windows\DigiData.Host.exe (DigiData)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Shutterfly Uploader.lnk [2017-05-10]
ShortcutTarget: Shutterfly Uploader.lnk -> C:\Program Files (x86)\Shutterfly Uploader\ThisLife.Uploader.exe (Shutterfly, Inc.)
 
==================== Internet (Whitelisted) ====================
 
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
 
Tcpip\Parameters: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
Tcpip\..\Interfaces\{fa3ce8d6-7afe-4ad0-a04f-b501407fe7a5}: [DhcpNameServer] 68.105.28.11 68.105.29.11 68.105.28.12
 
Internet Explorer:
==================
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.msn.com/HPDSK13/1
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxps://www.google.com/
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.msn.com/HPDSK13/1
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms}
SearchScopes: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = 
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll [2016-02-25] (HP)
BHO-x32: PlusIEEventHelper Class -> {551A852F-39A6-44A7-9C13-AFBEC9185A9D} -> C:\Program Files (x86)\Nuance\PDFViewer\Bin\PlusIEContextMenu.dll [2011-06-30] (Zeon Corporation)
BHO-x32: Java™ Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2013-03-06] (Microsoft Corporation)
BHO-x32: ZeonIEEventHelper Class -> {DA986D7D-CCAF-47B2-84FE-BFA1549BEBF9} -> C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
BHO-x32: Java™ Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-24] (Oracle Corporation)
BHO-x32: HP Network Check Helper -> {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} -> C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll [2016-02-25] (HP)
Toolbar: HKLM-x32 - DocuCom PDF - {E3286BF1-E654-42FF-B4A6-5E111731DF6B} - C:\Program Files (x86)\Nuance\PDFCreate\Bin\ZeonIEFavClient.dll [2011-03-26] (Zeon Corporation)
Toolbar: HKU\S-1-5-21-2671885098-678752524-1400920573-1001 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} -  No File
DPF: HKLM-x32 {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} hxxp://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1499697116239
DPF: HKLM-x32 {D66F9BB1-7D8E-4A96-9166-20FCC91CBFE9} hxxp://99.7.214.118/FDSH_DVR.CAB
DPF: HKLM-x32 {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} hxxps://secure.logmein.com//activex/ractrl.cab?lmi=3379
 
FireFox:
========
FF HKLM\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF Extension: (Kaspersky Protection) - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi [2017-04-28]
FF HKLM\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF HKLM-x32\...\Firefox\Extensions: [[email protected]] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\FFExt\light_plugin_firefox\addon.xpi
FF HKLM-x32\...\Thunderbird\Extensions: [[email protected]] - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird => not found
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files (x86)\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-24] (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.50907.0\npctrl.dll [2017-05-03] ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.33.5\npGoogleUpdate3.dll [2017-04-29] (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2014-12-02] (Adobe Systems Inc.)
FF Plugin-x32: ZEON/PDF,version=2.0 -> C:\Program Files (x86)\Nuance\PDFViewer\bin\nppdf.dll [2011-07-15] (Zeon Corporation)
FF Plugin HKU\S-1-5-21-2671885098-678752524-1400920573-1001: @citrixonline.com/appdetectorplugin -> C:\Users\AIRWORX 2\AppData\Local\Citrix\Plugins\104\npappdetector.dll [2014-04-02] (Citrix Online)
 
Chrome: 
=======
CHR DefaultProfile: Profile 9
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Guest Profile [2017-06-24]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9 [2017-07-17]
CHR Extension: (Google Docs) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\aohghmighlieiainnegkcijnfilokake [2017-07-10]
CHR Extension: (Google Drive) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\apdfllckaahabafndbhieahigkjlhalf [2017-07-10]
CHR Extension: (YouTube) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2017-07-10]
CHR Extension: (Kaspersky Protection) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\fhoibnponjcgjgcnfacekaijdbbplhib [2017-07-14]
CHR Extension: (Google Docs Offline) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2017-07-10]
CHR Extension: (Chrome Web Store Payments) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2017-07-10]
CHR Extension: (Gmail) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2017-07-10]
CHR Extension: (Chrome Media Router) - C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\Profile 9\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2017-07-17]
CHR Profile: C:\Users\AIRWORX 2\AppData\Local\Google\Chrome\User Data\System Profile [2017-07-14]
CHR HKLM\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
CHR HKLM-x32\...\Chrome\Extension: [fhoibnponjcgjgcnfacekaijdbbplhib] - hxxps://chrome.google.com/webstore/detail/fhoibnponjcgjgcnfacekaijdbbplhib
 
==================== Services (Whitelisted) ====================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AdobeActiveFileMonitor4.0; C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe [102400 2005-09-09] () [File not signed]
R2 AGSService; C:\Program Files (x86)\Common Files\Adobe\AdobeGCClient\AGSService.exe [2246256 2017-05-18] (Adobe Systems, Incorporated)
R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [351944 2015-11-04] (Advanced Micro Devices, Inc.)
S2 AVP17.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\avp.exe [241544 2016-06-28] (AO Kaspersky Lab)
R3 BrYNSvc; C:\Program Files (x86)\Browny02\BrYNSvc.exe [266240 2012-06-05] (Brother Industries, Ltd.) [File not signed]
S2 dbupdate; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
S3 dbupdatem; C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [143144 2016-08-24] (Dropbox, Inc.)
R2 DbxSvc; C:\WINDOWS\system32\DbxSvc.exe [49992 2017-07-12] (Dropbox, Inc.)
R2 ekrn; C:\Program Files\ESET\ESET Security\ekrn.exe [2625368 2017-07-11] (ESET)
R2 Fitbit Connect; C:\Program Files (x86)\Fitbit Connect\FitbitConnectService.exe [5906088 2015-10-28] (Fitbit, Inc.)
R2 HPSupportSolutionsFrameworkService; C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe [321896 2017-07-06] (HP Inc.)
S3 klvssbrigde64; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\vssbridge64.exe [77328 2016-06-28] (AO Kaspersky Lab)
S2 KSDE1.0.0; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Secure Connection 1.0\ksde.exe [241544 2016-06-28] (AO Kaspersky Lab)
S2 kss; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Security Scan\kss.exe [1556448 2015-12-15] (AO Kaspersky Lab)
S3 ksu; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Software Updater\kl_platf.exe [1565000 2016-11-26] (AO Kaspersky Lab)
R2 MySQL; C:\Program Files (x86)\MySQL\MySQL Server 5.0\my.ini [8934 2016-01-14] () [File not signed]
R2 PDFProFiltSrvPP; C:\Program Files (x86)\Nuance\PaperPort\PDFProFiltSrvPP.exe [77640 2013-05-14] (Nuance Communications, Inc.)
S3 ss_conn_service; C:\Program Files (x86)\Samsung\USB Drivers\27_ssconn\conn\ss_conn_service.exe [752224 2017-01-15] (DEVGURU Co., LTD.)
R2 STacSV; C:\Program Files\IDT\WDM\STacSV64.exe [339456 2013-11-20] (IDT, Inc.) [File not signed]
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [342264 2017-03-18] (Microsoft Corporation)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [102816 2017-07-14] (Microsoft Corporation)
 
===================== Drivers (Whitelisted) ======================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
R2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
R1 CLVirtualDrive; C:\WINDOWS\system32\DRIVERS\CLVirtualDrive.sys [91712 2013-03-15] (CyberLink)
R0 cm_km; C:\WINDOWS\System32\DRIVERS\cm_km.sys [238936 2016-06-10] (AO Kaspersky Lab)
R1 eamonm; C:\WINDOWS\System32\DRIVERS\eamonm.sys [132848 2017-07-11] (ESET)
R0 edevmon; C:\WINDOWS\System32\DRIVERS\edevmon.sys [107344 2017-03-09] (ESET)
S0 eelam; C:\WINDOWS\System32\DRIVERS\eelam.sys [14880 2017-03-09] (ESET)
R1 ehdrv; C:\WINDOWS\system32\DRIVERS\ehdrv.sys [178056 2017-03-09] (ESET)
S4 ekbdflt; C:\WINDOWS\system32\DRIVERS\ekbdflt.sys [50752 2017-03-09] (ESET)
R1 epfw; C:\WINDOWS\system32\DRIVERS\epfw.sys [78192 2017-03-09] (ESET)
R1 epfwwfp; C:\WINDOWS\system32\DRIVERS\epfwwfp.sys [101648 2017-03-09] (ESET)
S3 ESETCleanersDriver; C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys [181160 2017-06-28] (ESET)
R0 kl1; C:\WINDOWS\System32\DRIVERS\kl1.sys [554416 2016-06-02] (AO Kaspersky Lab)
R0 klbackupdisk; C:\WINDOWS\System32\DRIVERS\klbackupdisk.sys [63920 2016-06-07] (AO Kaspersky Lab)
R1 klbackupflt; C:\WINDOWS\System32\DRIVERS\klbackupflt.sys [86352 2016-06-15] (AO Kaspersky Lab)
R2 kldisk; C:\WINDOWS\system32\DRIVERS\kldisk.sys [78216 2016-05-31] (AO Kaspersky Lab)
S0 klelam; C:\WINDOWS\System32\DRIVERS\klelam.sys [28792 2016-03-31] (AO Kaspersky Lab)
R3 klflt; C:\WINDOWS\system32\DRIVERS\klflt.sys [197336 2017-04-28] (AO Kaspersky Lab)
S3 klids; C:\ProgramData\Kaspersky Lab\AVP17.0.0\Bases\klids.sys [187336 2017-07-14] (AO Kaspersky Lab)
S1 KLIF; C:\WINDOWS\System32\DRIVERS\klif.sys [1018592 2017-04-28] (AO Kaspersky Lab)
S1 KLIM6; C:\WINDOWS\system32\DRIVERS\klim6.sys [57424 2017-04-28] (AO Kaspersky Lab)
R3 klkbdflt; C:\WINDOWS\system32\DRIVERS\klkbdflt.sys [52136 2016-05-19] (AO Kaspersky Lab)
R3 klmouflt; C:\WINDOWS\system32\DRIVERS\klmouflt.sys [41656 2015-06-07] (Kaspersky Lab ZAO)
R1 klpd; C:\WINDOWS\System32\DRIVERS\klpd.sys [45488 2016-05-31] (AO Kaspersky Lab)
U0 klupd_klif_arkmon; C:\WINDOWS\System32\Drivers\klupd_klif_arkmon.sys [229288 2017-07-14] (AO Kaspersky Lab)
U3 klupd_klif_arkmon_097D7222; C:\ProgramData\Kaspersky Lab\AVP17.0.0\temp\097D722294B9C1FA6E514A088F2E6B6E\klupd_klif_arkmon.sys [229288 2017-07-14] (AO Kaspersky Lab)
U3 klupd_klif_klark; C:\WINDOWS\System32\Drivers\klupd_klif_klark.sys [251656 2017-07-14] (AO Kaspersky Lab)
U0 klupd_klif_klbg; C:\WINDOWS\System32\Drivers\klupd_klif_klbg.sys [112912 2017-07-14] (AO Kaspersky Lab)
U3 klupd_klif_mark; C:\WINDOWS\System32\Drivers\klupd_klif_mark.sys [173144 2017-07-14] (AO Kaspersky Lab)
R1 klwfp; C:\WINDOWS\system32\DRIVERS\klwfp.sys [85320 2016-06-18] (AO Kaspersky Lab)
R1 Klwtp; C:\WINDOWS\system32\DRIVERS\klwtp.sys [136416 2017-04-28] (AO Kaspersky Lab)
R1 kneps; C:\WINDOWS\system32\DRIVERS\kneps.sys [199392 2017-07-14] (AO Kaspersky Lab)
R2 NPF; C:\WINDOWS\system32\drivers\npf.sys [35344 2015-01-08] (CACE Technologies, Inc.)
R3 RTSUER; C:\WINDOWS\system32\Drivers\RtsUer.sys [402136 2016-10-27] (Realsil Semiconductor Corporation)
S3 SDFRd; C:\WINDOWS\System32\drivers\SDFRd.sys [31128 2017-03-18] ()
R0 vidsflt53; C:\WINDOWS\System32\DRIVERS\vsflt53.sys [141920 2016-03-03] (Acronis)
S3 WdBoot; C:\WINDOWS\system32\drivers\WdBoot.sys [44632 2017-03-18] (Microsoft Corporation)
R3 WdFilter; C:\WINDOWS\system32\drivers\WdFilter.sys [294816 2017-03-18] (Microsoft Corporation)
R3 WdNisDrv; C:\WINDOWS\System32\Drivers\WdNisDrv.sys [121248 2017-03-18] (Microsoft Corporation)
 
==================== NetSvcs (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
 
==================== One Month Created files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-17 10:26 - 2017-07-17 10:26 - 00041800 _____ (Sysinternals - www.sysinternals.com) C:\WINDOWS\system32\Drivers\PROCEXP152.SYS
2017-07-17 10:25 - 2017-07-17 10:25 - 02724512 _____ (Sysinternals - www.sysinternals.com) C:\Users\AIRWORX 2\Downloads\procexp.exe
2017-07-17 10:14 - 2017-07-17 10:14 - 00504650 _____ C:\Users\AIRWORX 2\SysInspector-AIRWORX2-PC-170717-072446.zip
2017-07-17 09:55 - 2017-07-17 09:55 - 00000000 _____ C:\WINDOWS\system32\wmic
2017-07-17 09:22 - 2017-07-17 09:22 - 141475088 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Downloads\msert (2).exe
2017-07-17 09:21 - 2017-07-17 09:21 - 07340032 _____ C:\Users\AIRWORX 2\Downloads\msert (1).exe
2017-07-17 09:14 - 2017-07-17 09:14 - 01048576 _____ C:\Users\AIRWORX 2\Downloads\msert.exe
2017-07-17 07:40 - 2017-07-17 07:40 - 06754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Downloads\esetonlinescanner_enu.exe
2017-07-17 07:11 - 2017-07-17 07:11 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\DBG
2017-07-17 03:31 - 2017-07-17 13:05 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Cleanup apps
2017-07-14 11:00 - 2017-07-14 11:00 - 00000000 ____D C:\Users\Public\Documents\MDMDiagnostics
2017-07-14 10:46 - 2012-10-24 12:44 - 00656048 _____ (WildTangent, Inc.) C:\ProgramData\uninstall2810124.exe
2017-07-14 10:40 - 2017-07-14 10:40 - 00000000 ____D C:\WINDOWS\System32\Tasks\S-1-5-21-2671885098-678752524-1400920573-1001
2017-07-14 09:14 - 2017-07-14 09:14 - 00000000 ____D C:\WINDOWS\PCHEALTH
2017-07-14 06:50 - 2017-07-14 06:50 - 00000020 ___SH C:\Users\AIRWORX 2\ntuser.ini
2017-07-14 06:32 - 2017-07-14 06:32 - 00000000 ____D C:\Windows.old
2017-07-14 06:30 - 2017-07-14 06:30 - 32688336 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsRaw.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 31652264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsRaw.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 23681536 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 23677440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edgehtml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 21353208 _____ (Microsoft Corporation) C:\WINDOWS\system32\shell32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 20504576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edgehtml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 20373408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\shell32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 19335168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 17364992 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 13839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 12786176 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieframe.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 11870720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieframe.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 08331264 _____ (Microsoft Corporation) C:\WINDOWS\system32\BingMaps.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 08318880 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntoskrnl.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 08238080 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakra.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 08211968 _____ (Microsoft Corporation) C:\WINDOWS\system32\mstscax.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07931392 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07904784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Protection.PlayReady.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07596544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mstscax.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07336448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Data.Pdf.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07325584 _____ (Microsoft Corporation) C:\WINDOWS\system32\windows.storage.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 07149056 _____ (Microsoft Corporation) C:\WINDOWS\system32\mos.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 06759512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.Protection.PlayReady.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 06728192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 06554928 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 06287360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Chakra.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 06123520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mos.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05961216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Data.Pdf.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05892096 _____ (Microsoft Corporation) C:\WINDOWS\system32\d2d1.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05820984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\windows.storage.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05806048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Media.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05719040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BingMaps.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05557760 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbgeng.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05477088 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneCoreUAPCommonProxyStub.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 05225984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d2d1.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04847424 _____ (Microsoft Corporation) C:\WINDOWS\explorer.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 04730880 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04707840 _____ (Microsoft Corporation) C:\WINDOWS\system32\ExplorerFrame.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04559360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbgeng.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04536320 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFMediaEngine.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04469840 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\explorer.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 04447744 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_nt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04417024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ExplorerFrame.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04396032 _____ (Microsoft Corporation) C:\WINDOWS\system32\D3DCompiler_47.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 04056576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFMediaEngine.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03803136 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsThresholdAdminFlowUI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03784704 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapRouter.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03670016 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kfull.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 03667456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\D3DCompiler_47.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03656704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\jscript9.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03377664 _____ (Microsoft Corporation) C:\WINDOWS\system32\tquery.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03332096 _____ (Microsoft Corporation) C:\WINDOWS\system32\SRH.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03307008 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininet.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03204096 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03139584 _____ (Microsoft Corporation) C:\WINDOWS\system32\msftedit.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03059200 _____ (Microsoft Corporation) C:\WINDOWS\system32\NetworkMobileSettings.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 03057664 _____ (Microsoft Corporation) C:\WINDOWS\system32\CertEnroll.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02969880 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreUIComponents.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02956800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\win32kfull.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 02938880 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputService.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02873344 _____ (Microsoft Corporation) C:\WINDOWS\system32\themeui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02859520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininet.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02829824 _____ (Microsoft Corporation) C:\WINDOWS\system32\DWrite.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02814464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\themeui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02804736 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentServer.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02782720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msftedit.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02750464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CertEnroll.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02681760 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tcpip.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 02679296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SRH.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02671616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tquery.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02649600 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmcore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02645688 _____ (Microsoft Corporation) C:\WINDOWS\system32\iertutil.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02597888 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssrch.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02588160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapRouter.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02499584 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.pcshell.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02475136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\d3d10warp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02444696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgkrnl.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 02444288 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuaueng.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02399728 _____ (Microsoft Corporation) C:\WINDOWS\system32\KernelBase.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02330520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\combase.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02327456 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ntfs.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 02298368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmcore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02259760 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreUIComponents.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02211328 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputService.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Resources.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02199552 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Resources.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02177024 _____ (Microsoft Corporation) C:\WINDOWS\system32\OpcServices.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02171392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Bluetooth.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02165752 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iertutil.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02132480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mssrch.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02077184 _____ (Microsoft Corporation) C:\WINDOWS\system32\inetcpl.cpl
2017-07-14 06:30 - 2017-07-14 06:30 - 02055168 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32kbase.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 02021680 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpmde.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 02008576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\inetcpl.cpl
2017-07-14 06:30 - 2017-07-14 06:30 - 01930320 _____ (Microsoft Corporation) C:\WINDOWS\system32\ntdll.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01888256 _____ (Microsoft Corporation) C:\WINDOWS\system32\FntCache.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01886208 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.onecore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01878016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AzureSettingSyncProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01839872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\KernelBase.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01818624 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIAutomationCore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01812480 _____ (Microsoft Corporation) C:\WINDOWS\system32\msxml3.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01802240 _____ (Microsoft Corporation) C:\WINDOWS\system32\urlmon.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01760264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecs.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01713664 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01703424 _____ (Microsoft Corporation) C:\WINDOWS\system32\aitstatic.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01674240 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpncore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01670496 _____ (Microsoft Corporation) C:\WINDOWS\system32\winmde.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01640448 _____ (Microsoft Corporation) C:\WINDOWS\system32\GdiPlus.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01626624 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\urlmon.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01620368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ntdll.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01565184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml3.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01564576 _____ (Microsoft Corporation) C:\WINDOWS\system32\appraiser.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01529384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winmde.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01518088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecs.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01494016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActiveSyncProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01492480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Bluetooth.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01468416 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentExtensions.desktop.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01451008 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIAutomationCore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01448960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\GdiPlus.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01425920 _____ (Microsoft Corporation) C:\WINDOWS\system32\certutil.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01420800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Xaml.Maps.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01403392 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01396224 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwansvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01395152 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.efi
2017-07-14 06:30 - 2017-07-14 06:30 - 01357824 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01355264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OpcServices.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01339352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wmpmde.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01337848 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01325968 _____ (Microsoft Corporation) C:\WINDOWS\system32\ole32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01305088 _____ (Microsoft Corporation) C:\WINDOWS\system32\dosvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01301504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01293824 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadtb.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01285120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dbghelp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01260544 _____ (Microsoft Corporation) C:\WINDOWS\system32\GamePanel.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01248768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AzureSettingSyncProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01242528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ndis.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 01237504 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Xaml.Maps.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01220072 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfsvr.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01214880 _____ (Microsoft Corporation) C:\WINDOWS\system32\aeinv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01195240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01186464 _____ (Microsoft Corporation) C:\WINDOWS\system32\winload.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01178528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxPackaging.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01177600 _____ (Microsoft Corporation) C:\WINDOWS\system32\Unistore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01171968 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certutil.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01171032 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcomp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01150784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ucrtbase.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01147288 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvix64.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01142272 _____ (Microsoft Corporation) C:\WINDOWS\system32\localspl.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01121928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfsvr.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01106848 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\http.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 01077496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webservices.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01076736 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinui.appcore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01065104 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.efi
2017-07-14 06:30 - 2017-07-14 06:30 - 01057832 _____ (Microsoft Corporation) C:\WINDOWS\system32\MrmCoreR.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01055648 _____ (Microsoft Corporation) C:\WINDOWS\system32\LicenseManager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01054280 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01050624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01024928 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvax64.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 01019904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aadtb.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 01017760 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecConfig.efi
2017-07-14 06:30 - 2017-07-14 06:30 - 00988168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ole32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00986112 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00985600 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWorkspace.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00970752 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctfuimanager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00969728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Unistore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00965024 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.efi
2017-07-14 06:30 - 2017-07-14 06:30 - 00952832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comdlg32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00949920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dcomp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00947712 _____ (Microsoft Corporation) C:\WINDOWS\system32\HoloSI.PCShell.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00942592 _____ (Microsoft Corporation) C:\WINDOWS\system32\wbiosrvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00925696 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpcWebFilter.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00923040 _____ (Microsoft Corporation) C:\WINDOWS\system32\CoreMessaging.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00922112 _____ (Microsoft Corporation) C:\WINDOWS\system32\kerberos.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00916992 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcastdvr.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00899824 _____ (Microsoft Corporation) C:\WINDOWS\system32\winresume.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctfuimanager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00899072 _____ (Microsoft Corporation) C:\WINDOWS\system32\SmartcardCredentialProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00873472 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasmans.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00872472 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipSVC.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00864240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00859136 _____ (Microsoft Corporation) C:\WINDOWS\system32\uDWM.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00847872 _____ (Microsoft Corporation) C:\WINDOWS\system32\bisrv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00840192 _____ (Microsoft Corporation) C:\WINDOWS\system32\fveapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00833160 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeManagerObj.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00823296 _____ (Microsoft Corporation) C:\WINDOWS\system32\MbaeApi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00821664 _____ (Microsoft Corporation) C:\WINDOWS\system32\hvloader.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00820128 _____ (Microsoft Corporation) C:\WINDOWS\system32\WWAHost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00809984 _____ (Microsoft Corporation) C:\WINDOWS\system32\rasapi32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00802816 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmsvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00791040 _____ (Microsoft Corporation) C:\WINDOWS\system32\certca.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00790016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00787712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpcrt4.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00787456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wuapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00778240 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyHrtfEnc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00760832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rasapi32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00757248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\WdiWiFi.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00754592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\LicenseManager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kerberos.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00751104 _____ (Microsoft Corporation) C:\WINDOWS\system32\msfeeds.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00750560 _____ (Microsoft Corporation) C:\WINDOWS\system32\fontdrvhost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00750496 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WWAHost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00734208 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcastdvr.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00722432 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusUpdateHandlers.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00706560 _____ (Microsoft Corporation) C:\WINDOWS\system32\winlogon.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00696320 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmsys.cpl
2017-07-14 06:30 - 2017-07-14 06:30 - 00692736 _____ (Microsoft Corporation) C:\WINDOWS\system32\jscript9diag.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00687616 _____ (Microsoft Corporation) C:\WINDOWS\system32\LogonController.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00681984 _____ (Microsoft Corporation) C:\WINDOWS\system32\usocore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00663040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msfeeds.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00648192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SmartcardCredentialProvider.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MbaeApi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00646656 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockHostingFramework.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00646144 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmsys.cpl
2017-07-14 06:30 - 2017-07-14 06:30 - 00641024 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certca.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00636416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WpcWebFilter.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00632832 _____ (Microsoft Corporation) C:\WINDOWS\system32\tileobjserver.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00629152 _____ (Microsoft Corporation) C:\WINDOWS\system32\generaltel.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00626528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\fontdrvhost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00626176 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Bluetooth.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00625152 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00621056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SndVolSSO.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SndVolSSO.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00600064 _____ (Microsoft Corporation) C:\WINDOWS\system32\FrameServer.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00588800 _____ (Microsoft Corporation) C:\WINDOWS\system32\vbscript.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00585216 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppReadiness.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\apphelp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00583304 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00583160 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CoreMessaging.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00577024 _____ (Microsoft Corporation) C:\WINDOWS\system32\duser.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00570880 _____ (Microsoft Corporation) C:\WINDOWS\system32\PhotoScreensaver.scr
2017-07-14 06:30 - 2017-07-14 06:30 - 00563712 _____ (Microsoft Corporation) C:\WINDOWS\system32\DevicePairing.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00558920 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00555008 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgrSvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00554392 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBHUB3.SYS
2017-07-14 06:30 - 2017-07-14 06:30 - 00551424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Payments.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00548864 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorService.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00545792 _____ (Microsoft Corporation) C:\WINDOWS\system32\winspool.drv
2017-07-14 06:30 - 2017-07-14 06:30 - 00544160 _____ (Microsoft Corporation) C:\WINDOWS\system32\devinv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00536064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Management.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00527360 _____ (Microsoft Corporation) C:\WINDOWS\system32\aadcloudap.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00520704 _____ (Microsoft Corporation) C:\WINDOWS\system32\daxexec.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00519584 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netio.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00510976 _____ (Microsoft Corporation) C:\WINDOWS\system32\TDLMigration.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00508416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PhotoScreensaver.scr
2017-07-14 06:30 - 2017-07-14 06:30 - 00506368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\vbscript.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00502784 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DevicePairing.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.BlueLightReduction.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00497152 _____ (Microsoft Corporation) C:\WINDOWS\system32\rastls.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00472728 _____ (Microsoft Corporation) C:\WINDOWS\system32\policymanager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00471040 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VAN.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00467504 _____ (Microsoft Corporation) C:\WINDOWS\system32\MFCaptureEngine.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00455680 _____ (Microsoft Corporation) C:\WINDOWS\system32\certcli.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00455104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSAudDecMFT.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00446464 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rastls.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00443728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MFCaptureEngine.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00443392 _____ (Microsoft Corporation) C:\WINDOWS\system32\PerceptionSimulationExtensions.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00438096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00433152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Bluetooth.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00430080 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToDevice.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00427008 _____ (Microsoft Corporation) C:\WINDOWS\system32\provengine.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00426912 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostCommon.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00422400 _____ (Microsoft Corporation) C:\WINDOWS\system32\WpAXHolder.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00417792 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgentUserBroker.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00417280 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleacc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00412160 _____ (Microsoft Corporation) C:\WINDOWS\system32\SensorsApi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00411992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSAudDecMFT.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00411648 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActivationManager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00411136 _____ (Microsoft Corporation) C:\WINDOWS\system32\updatehandlers.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00411040 _____ (Microsoft Corporation) C:\WINDOWS\system32\msv1_0.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhext.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00406528 _____ (Microsoft Corporation) C:\WINDOWS\system32\InputSwitch.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00406072 _____ (Microsoft Corporation) C:\WINDOWS\system32\MMDevAPI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00406032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\policymanager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00400896 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXTaskFactory.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00397312 _____ (Microsoft Corporation) C:\WINDOWS\system32\rascustom.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Internal.Management.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00391168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WMPhoto.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00387584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Payments.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00386560 _____ (Microsoft Corporation) C:\WINDOWS\system32\iedkcs32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00382368 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\clfs.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00374784 _____ (Microsoft Corporation) C:\WINDOWS\system32\InstallAgent.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00372128 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHost.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00370176 _____ (Microsoft Corporation) C:\WINDOWS\system32\msinfo32.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00368128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgentUserBroker.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\daxexec.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00365056 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Notifications.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchProtocolHost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00360960 _____ (Microsoft Corporation) C:\WINDOWS\system32\ConhostV2.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00357888 _____ (Microsoft Corporation) C:\WINDOWS\system32\Narrator.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00356864 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ActivationManager.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00354400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MMDevAPI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00353280 _____ (Microsoft Corporation) C:\WINDOWS\system32\Wldap32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00349600 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msv1_0.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00346016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostCommon.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00342528 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WMPhoto.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00342016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\certcli.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msinfo32.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00338432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iedkcs32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00336320 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthService.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00335872 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinDataModelServer.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00335776 _____ (Microsoft Corporation) C:\WINDOWS\system32\dcntel.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00334848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToDevice.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00334240 _____ (Microsoft Corporation) C:\WINDOWS\system32\invagent.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00331776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleacc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webplatstorageserver.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00329728 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InstallAgent.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00329216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SensorsApi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00328704 _____ (Microsoft Corporation) C:\WINDOWS\system32\PsmServiceExtHost.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00327168 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModel.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00318232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininit.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsEnvironment.Desktop.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Wldap32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00312320 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchProtocolHost.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00299520 _____ (Microsoft Corporation) C:\WINDOWS\system32\AboveLockAppHost.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00293376 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotification.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00290816 _____ (Microsoft Corporation) C:\WINDOWS\system32\omadmclient.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00285696 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb10.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00279968 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\msiscsi.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00278944 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\thumbcache.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowsCodecsExt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00274944 _____ (Microsoft Corporation) C:\WINDOWS\system32\dxtrans.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00272896 _____ (Microsoft Corporation) C:\WINDOWS\system32\PlayToReceiver.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00266240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dxtrans.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00256000 _____ (Microsoft Corporation) C:\WINDOWS\system32\domgmt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00255904 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppxAllUserStore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00254168 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfps.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00253440 _____ (Microsoft Corporation) C:\WINDOWS\system32\edputil.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00251392 _____ (Microsoft Corporation) C:\WINDOWS\system32\scksp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00250368 _____ (Microsoft Corporation) C:\WINDOWS\system32\SCardSvr.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00247808 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AboveLockAppHost.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WindowsCodecsExt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00241152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wdmaud.drv
2017-07-14 06:30 - 2017-07-14 06:30 - 00233376 _____ (Microsoft Corporation) C:\WINDOWS\system32\aepic.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00231936 _____ (Microsoft Corporation) C:\WINDOWS\system32\DolbyMATEnc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00230912 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\edputil.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\SIHClient.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00228256 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxsmb20.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00226304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\scksp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00216064 _____ (Microsoft Corporation) C:\WINDOWS\system32\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00209920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wdmaud.drv
2017-07-14 06:30 - 2017-07-14 06:30 - 00208384 _____ (Microsoft Corporation) C:\WINDOWS\system32\psmsrv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00205824 _____ (Microsoft Corporation) C:\WINDOWS\system32\sensrsvc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00205312 _____ (Microsoft Corporation) C:\WINDOWS\system32\ClipboardServer.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00204192 _____ (Microsoft Corporation) C:\WINDOWS\system32\basecsp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00203168 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostBroker.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00201216 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\credprovhost.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00200192 _____ (Microsoft Corporation) C:\WINDOWS\system32\ScDeviceEnum.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00192416 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\aepic.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00189952 _____ (Microsoft Corporation) C:\WINDOWS\system32\certprop.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00189440 _____ (Microsoft Corporation) C:\WINDOWS\system32\BluetoothApis.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00188928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wincredui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00181656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppxAllUserStore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00179608 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudExperienceHostUser.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00178176 _____ (Microsoft Corporation) C:\WINDOWS\system32\EditionUpgradeHelper.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00176032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\basecsp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\system32\prntvpt.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00173568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ClipboardServer.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00165888 _____ (Microsoft Corporation) C:\WINDOWS\system32\storewuauth.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00157696 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\rpchttp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00151552 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wincredui.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00147800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Clipc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00144384 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Profile.RetailInfo.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00142752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\wcifs.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00140288 _____ (Microsoft Corporation) C:\WINDOWS\system32\iepeers.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00139776 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\BluetoothApis.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00138752 _____ (Microsoft Corporation) C:\WINDOWS\system32\DMPushRouterCore.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00138656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudExperienceHostUser.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00137216 _____ (Microsoft Corporation) C:\WINDOWS\system32\raschap.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00136096 _____ (Microsoft Corporation) C:\WINDOWS\system32\acmigration.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00135680 _____ (Microsoft Corporation) C:\WINDOWS\system32\sendmail.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00132096 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Microsoft.Bluetooth.Profiles.Gatt.Interface.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00129184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00125344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dwmapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00124928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iepeers.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00123520 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Clipc.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00121856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sendmail.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00119384 _____ (Microsoft Corporation) C:\WINDOWS\system32\dmcmnutils.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00117664 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\pdc.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00117248 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\raschap.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00115712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\bridge.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00114688 _____ (Microsoft Corporation) C:\WINDOWS\system32\officecsp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00113152 _____ (Microsoft Corporation) C:\WINDOWS\system32\wuuhosdeployment.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00111104 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Profile.RetailInfo.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00110592 _____ (Microsoft Corporation) C:\WINDOWS\system32\Chakradiag.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00102312 _____ (Microsoft Corporation) C:\WINDOWS\system32\CredentialUIBroker.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00096672 _____ (Microsoft Corporation) C:\WINDOWS\system32\CompatTelRunner.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mshtmled.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00096256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ActiveSyncCsp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00096128 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dmcmnutils.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00095232 _____ (Microsoft Corporation) C:\WINDOWS\system32\wudriver.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00094624 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdpudd.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00089088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\olepro32.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00086528 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\hdaudbus.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00084992 _____ (Microsoft Corporation) C:\WINDOWS\system32\MshtmlDac.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00081920 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudDomainJoinAUG.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\system32\wwanprotdim.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00080384 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mshtmled.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00079872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wudriver.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MshtmlDac.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00064000 _____ (Microsoft Corporation) C:\WINDOWS\system32\WFDSConMgr.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00062464 _____ (Microsoft Corporation) C:\WINDOWS\system32\dataclen.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00059392 _____ (Microsoft Corporation) C:\WINDOWS\system32\DmApiSetExtImplDesktop.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00058488 _____ (Microsoft Corporation) C:\WINDOWS\system32\lsass.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00058368 _____ (Microsoft Corporation) C:\WINDOWS\system32\csrsrv.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\WinBioDataModelOOBE.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00056832 _____ (Microsoft Corporation) C:\WINDOWS\system32\cldapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00052224 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\dataclen.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cldapi.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00049656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msasn1.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00045056 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBrokerUI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00041376 _____ (Microsoft Corporation) C:\WINDOWS\system32\wininitext.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00038400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBrokerUI.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00035232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wininitext.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00034720 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCensus.exe
2017-07-14 06:30 - 2017-07-14 06:30 - 00032768 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mskssrv.sys
2017-07-14 06:30 - 2017-07-14 06:30 - 00031932 _____ C:\WINDOWS\system32\edgehtmlpluginpolicy.bin
2017-07-14 06:30 - 2017-07-14 06:30 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\eapprovp.dll
2017-07-14 06:30 - 2017-07-14 06:30 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\eapprovp.dll
2017-07-14 06:29 - 2013-11-20 10:43 - 01897984 _____ (IDT, Inc.) C:\WINDOWS\system32\IDTNC64.cpl
2017-07-14 06:29 - 2013-11-20 10:43 - 01703424 _____ (IDT, Inc.) C:\WINDOWS\sttray64.exe
2017-07-14 06:29 - 2013-11-20 10:43 - 00697856 ____N (IDT, Inc.) C:\WINDOWS\system32\stapi64.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 06726656 _____ (Microsoft Corporation) C:\WINDOWS\system32\mspaint.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 06535168 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mspaint.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 04709528 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfcore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 04672848 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfcore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 04175872 _____ (Microsoft Corporation) C:\WINDOWS\system32\StartTileData.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 03135488 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapGeocoder.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 03116184 _____ (Microsoft Corporation) C:\WINDOWS\system32\combase.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02765824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Shell.UnifiedTile.CuratedTileCollections.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02730496 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreen.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 02625024 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Logon.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02604256 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmp4srcsnk.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02516480 _____ (Microsoft Corporation) C:\WINDOWS\system32\diagtrack.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02438656 _____ (Microsoft Corporation) C:\WINDOWS\system32\ResetEngine.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02424016 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmp4srcsnk.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02347520 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceFlows.DataModel.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02341376 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DWrite.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02088960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MapGeocoder.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 02085280 _____ (Microsoft Corporation) C:\WINDOWS\system32\UpdateAgent.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01984000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DeviceFlows.DataModel.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01911752 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.ApplicationModel.Store.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01852776 _____ (Microsoft Corporation) C:\WINDOWS\system32\crypt32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01706496 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Immersive.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01700408 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfplat.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01657344 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsPrint.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01628160 _____ (Microsoft Corporation) C:\WINDOWS\system32\comsvcs.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01611776 _____ (Microsoft Corporation) C:\WINDOWS\system32\SpeechPal.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01605632 _____ (Microsoft Corporation) C:\WINDOWS\system32\quartz.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01600512 _____ (Microsoft Corporation) C:\WINDOWS\system32\dbghelp.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01596600 _____ (Microsoft Corporation) C:\WINDOWS\system32\gdi32full.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01583616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieapfltr.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01557288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\crypt32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01536512 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.UI.Immersive.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01506816 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\quartz.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01506712 _____ (Microsoft Corporation) C:\WINDOWS\system32\twinapi.appcore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01474800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.ApplicationModel.Store.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01463296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieapfltr.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01459728 _____ (Microsoft Corporation) C:\WINDOWS\system32\msctf.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01455592 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfplat.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01433600 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettings.Handlers.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01409048 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\gdi32full.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01333136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msctf.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01320352 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpx.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01302528 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVPXENC.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01292288 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MSVPXENC.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01275904 _____ (Microsoft Corporation) C:\WINDOWS\system32\ShareHost.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01269760 _____ (Microsoft Corporation) C:\WINDOWS\system32\enterprisecsps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01266544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinapi.appcore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01257472 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnapps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01242624 _____ (Microsoft Corporation) C:\WINDOWS\system32\SharedStartModel.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01141760 _____ (Microsoft Corporation) C:\WINDOWS\system32\MapsStore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01102848 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncCore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01085440 _____ (Microsoft Corporation) C:\WINDOWS\system32\rpcss.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01078272 _____ (Microsoft Corporation) C:\WINDOWS\system32\StoreAgent.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01067008 _____ (Microsoft Corporation) C:\WINDOWS\system32\XboxNetApiSvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01060352 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsPrint.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01054208 _____ (Microsoft Corporation) C:\WINDOWS\system32\TokenBroker.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\ngcsvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01046016 _____ (Microsoft Corporation) C:\WINDOWS\system32\comdlg32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01035264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ShareHost.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01028608 _____ (Microsoft Corporation) C:\WINDOWS\system32\modernexecserver.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 01003624 _____ (Microsoft Corporation) C:\WINDOWS\system32\ucrtbase.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00987648 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wpnapps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00975360 _____ (Microsoft Corporation) C:\WINDOWS\HelpPane.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00974848 _____ (Microsoft Corporation) C:\WINDOWS\system32\mmgaserver.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00972800 _____ (Microsoft Corporation) C:\WINDOWS\system32\sysmain.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\cdpsvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00970240 _____ (Microsoft Corporation) C:\WINDOWS\system32\autochk.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00961952 _____ (Microsoft Corporation) C:\WINDOWS\system32\efscore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00933376 _____ (Microsoft Corporation) C:\WINDOWS\system32\SearchIndexer.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00909824 _____ (Microsoft Corporation) C:\WINDOWS\system32\ISM.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00909312 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncCore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00899584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\twinui.appcore.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00892416 _____ (Microsoft Corporation) C:\WINDOWS\system32\MessagingDataModel2.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00891904 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\autochk.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00866816 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSMDesktopProvider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00864256 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationController.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00827392 _____ (Microsoft Corporation) C:\WINDOWS\system32\win32spl.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00826368 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSMDesktopProvider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00809472 _____ (Microsoft Corporation) C:\WINDOWS\system32\SecurityHealthSSO.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00807424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\StoreAgent.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00805888 _____ (Microsoft Corporation) C:\WINDOWS\system32\ieproxy.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00799232 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TokenBroker.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00797184 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SearchIndexer.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00778240 _____ C:\WINDOWS\system32\MBR2GPT.EXE
2017-07-14 06:22 - 2017-07-14 06:22 - 00777400 _____ (Microsoft Corporation) C:\WINDOWS\system32\oleaut32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00754176 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\MessagingDataModel2.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00750080 _____ (Microsoft Corporation) C:\WINDOWS\system32\StorSvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00741784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Internal.Shell.Broker.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00731136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mmgaserver.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00730016 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\vhdmp.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00722944 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv2.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00716440 _____ (Microsoft Corporation) C:\WINDOWS\system32\MSVideoDSP.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00712608 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms2.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00708712 _____ (Microsoft Corporation) C:\WINDOWS\system32\kernel32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00673280 _____ (Microsoft Corporation) C:\WINDOWS\system32\LockAppBroker.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00673112 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppResolver.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00667040 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00660384 _____ (Microsoft Corporation) C:\WINDOWS\system32\comctl32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00654976 _____ (Microsoft Corporation) C:\WINDOWS\system32\AppXDeploymentClient.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00651680 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingSyncHost.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00647168 _____ (Microsoft Corporation) C:\WINDOWS\system32\RDXService.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00641536 _____ (Microsoft Corporation) C:\WINDOWS\system32\rdbui.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00616960 _____ (Microsoft Corporation) C:\WINDOWS\system32\WindowManagement.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00606960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\oleaut32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00601088 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.System.Launcher.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00599576 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\kernel32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00586240 _____ (Microsoft Corporation) C:\WINDOWS\system32\OneDriveSettingSyncProvider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UIRibbonRes.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00584192 _____ (Microsoft Corporation) C:\WINDOWS\system32\UIRibbonRes.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00573856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\comctl32.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00559000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\SettingSyncHost.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00557568 _____ (Microsoft Corporation) C:\WINDOWS\system32\wpnprv.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00551936 _____ (Microsoft Corporation) C:\WINDOWS\system32\TpmCoreProvisioning.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00549888 _____ (Microsoft Corporation) C:\WINDOWS\system32\DictationManager.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00546208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storport.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00543648 _____ (Microsoft Corporation) C:\WINDOWS\system32\securekernel.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00524800 _____ (Microsoft Corporation) C:\WINDOWS\system32\TileDataRepository.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00523296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppResolver.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00519680 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AppXDeploymentClient.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00491520 _____ (Microsoft Corporation) C:\WINDOWS\system32\SettingsHandlers_Display.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00476672 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\OneDriveSettingSyncProvider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00476160 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.Core.TextInput.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00467456 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TpmCoreProvisioning.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00457728 _____ (Microsoft Corporation) C:\WINDOWS\system32\webplatstorageserver.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00450048 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdedit.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00444928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.System.Launcher.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00439808 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Devices.Midi.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00433664 _____ (Microsoft Corporation) C:\WINDOWS\system32\msIso.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00429568 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\winspool.drv
2017-07-14 06:22 - 2017-07-14 06:22 - 00414208 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\srv.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00409504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dxgmms1.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00394240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\DictationManager.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00392704 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PlayToManager.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00388000 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\USBXHCI.SYS
2017-07-14 06:22 - 2017-07-14 06:22 - 00387928 _____ (Microsoft Corporation) C:\WINDOWS\system32\wmpps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00382368 _____ (Adobe Systems Incorporated) C:\WINDOWS\system32\atmfd.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00370928 _____ (Microsoft Corporation) C:\WINDOWS\system32\SystemSettingsAdminFlows.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00364032 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msIso.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00363424 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\fastfat.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00358400 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ieproxy.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00354360 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bcryptprimitives.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00354304 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\InputSwitch.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00347136 _____ (Microsoft Corporation) C:\WINDOWS\system32\XpsDocumentTargetPrint.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00334336 _____ (Microsoft Corporation) C:\WINDOWS\system32\wc_storage.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00332800 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Devices.Midi.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00321376 _____ (Microsoft Corporation) C:\WINDOWS\system32\capauthz.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00315392 _____ (Microsoft Corporation) C:\WINDOWS\system32\NotificationObjFactory.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00311200 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\atmfd.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00301056 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseAppMgmtSvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00296448 _____ (Microsoft Corporation) C:\WINDOWS\system32\CloudBackupSettings.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00287648 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\sdbus.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00282112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\VEEventDispatcher.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00280064 _____ (Microsoft Corporation) C:\WINDOWS\system32\WiFiDisplay.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00277504 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\xboxgip.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00271872 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Security.Authentication.Identity.Provider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00266640 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\capauthz.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00259400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotifyIcon.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00257024 _____ (Microsoft Corporation) C:\WINDOWS\system32\webcheck.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00252928 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\XpsDocumentTargetPrint.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00251904 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Gaming.Preview.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00233472 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WiFiDisplay.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\webcheck.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00232960 _____ (Microsoft Corporation) C:\WINDOWS\system32\wcmcsp.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\CloudBackupSettings.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00232448 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Web.Diagnostics.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00224256 _____ (Microsoft Corporation) C:\WINDOWS\system32\ie4uinit.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00221184 _____ (Microsoft Corporation) C:\WINDOWS\system32\devicengccredprov.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00219040 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tpm.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00218624 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.Media.Streaming.ps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00211872 _____ (Microsoft Corporation) C:\WINDOWS\system32\browserbroker.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00209408 _____ (Microsoft Corporation) C:\WINDOWS\system32\smartscreenps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00208896 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.UI.AppDefaults.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00203776 _____ (Microsoft Corporation) C:\WINDOWS\system32\PackageStateRoaming.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00199680 _____ (Microsoft Corporation) C:\WINDOWS\system32\RstrtMgr.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00198656 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Security.Authentication.Identity.Provider.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00197120 _____ (Microsoft Corporation) C:\WINDOWS\system32\bcdboot.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00192512 _____ (Microsoft Corporation) C:\WINDOWS\system32\Windows.SharedPC.AccountManager.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00188824 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dumpsd.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00175616 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PackageStateRoaming.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Windows.Web.Diagnostics.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00174080 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\RstrtMgr.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00169984 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\devicengccredprov.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00164864 _____ (Microsoft Corporation) C:\WINDOWS\system32\EnterpriseModernAppMgmtCSP.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00159744 _____ (Microsoft Corporation) C:\WINDOWS\system32\NPSM.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00155136 _____ (Microsoft Corporation) C:\WINDOWS\system32\VEStoreEventHandlers.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00149504 _____ (Microsoft Corporation) C:\WINDOWS\system32\embeddedmodesvc.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00148480 _____ (Microsoft Corporation) C:\WINDOWS\system32\umpo.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00144288 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\storahci.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00142848 _____ (Microsoft Corporation) C:\WINDOWS\system32\dwmredir.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00141824 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\smartscreenps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00133120 _____ (Microsoft Corporation) C:\WINDOWS\system32\XblGameSaveExt.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00130464 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tm.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\NPSM.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00128000 _____ (Microsoft Corporation) C:\WINDOWS\system32\mssprxy.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00119712 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\tdx.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00119296 _____ (Microsoft Corporation) C:\WINDOWS\system32\UserDataTimeUtil.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00118784 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\netvsc.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00112544 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\dam.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00105456 _____ (Microsoft Corporation) C:\WINDOWS\system32\imagehlp.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00102400 _____ (Microsoft Corporation) C:\WINDOWS\system32\MusNotificationUx.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00099328 _____ (Microsoft Corporation) C:\WINDOWS\system32\utcutil.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00095584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\imagehlp.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00094720 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\UserDataTimeUtil.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00091648 _____ (Microsoft Corporation) C:\WINDOWS\system32\mfmjpegdec.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00088576 _____ (Microsoft Corporation) C:\WINDOWS\system32\winsrvext.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00087552 _____ (Microsoft Corporation) C:\WINDOWS\system32\asycfilt.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00086016 _____ C:\WINDOWS\system32\xboxgipsynthetic.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00082944 _____ (Microsoft Corporation) C:\WINDOWS\system32\tdc.ocx
2017-07-14 06:22 - 2017-07-14 06:22 - 00081408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\mfmjpegdec.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00078848 _____ (Microsoft Corporation) C:\WINDOWS\system32\offreg.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00078336 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\asycfilt.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00076800 _____ (Microsoft Corporation) C:\WINDOWS\system32\DeviceCredentialDeployment.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00072192 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tdc.ocx
2017-07-14 06:22 - 2017-07-14 06:22 - 00064512 _____ (Microsoft Corporation) C:\WINDOWS\bfsvc.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00061952 _____ (Microsoft Corporation) C:\WINDOWS\system32\vss_ps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00059904 _____ C:\WINDOWS\SysWOW64\xboxgipsynthetic.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00057856 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\offreg.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00052736 _____ (Microsoft Corporation) C:\WINDOWS\system32\musdialoghandlers.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00050176 _____ (Microsoft Corporation) C:\WINDOWS\system32\catsrvps.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00047104 _____ (Adobe Systems) C:\WINDOWS\system32\atmlib.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00038912 _____ (Adobe Systems) C:\WINDOWS\SysWOW64\atmlib.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00035840 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\BasicRender.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00029696 _____ (Microsoft Corporation) C:\WINDOWS\system32\odbcconf.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00027136 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ksthunk.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00027040 _____ (Microsoft Corporation) C:\WINDOWS\system32\browser_broker.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00025088 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\odbcconf.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00015872 _____ (Microsoft Corporation) C:\WINDOWS\system32\snmptrap.exe
2017-07-14 06:22 - 2017-07-14 06:22 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\rootmdm.sys
2017-07-14 06:22 - 2017-07-14 06:22 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\tzres.dll
2017-07-14 06:22 - 2017-07-14 06:22 - 00002560 _____ (Microsoft Corporation) C:\WINDOWS\system32\tzres.dll
2017-07-14 06:20 - 2017-07-14 06:23 - 00015243 _____ C:\WINDOWS\diagwrn.xml
2017-07-14 06:20 - 2017-07-14 06:23 - 00015243 _____ C:\WINDOWS\diagerr.xml
2017-07-14 06:17 - 2017-07-14 06:17 - 00008192 _____ C:\WINDOWS\system32\config\userdiff
2017-07-14 06:17 - 2017-07-14 05:36 - 00000000 ____D C:\WINDOWS\ServiceProfiles
2017-07-14 06:14 - 2017-07-14 06:14 - 00000000 ____D C:\Program Files\Reference Assemblies
2017-07-14 06:14 - 2017-07-14 06:14 - 00000000 ____D C:\Program Files\MSBuild
2017-07-14 06:14 - 2017-07-14 06:14 - 00000000 ____D C:\Program Files (x86)\Reference Assemblies
2017-07-14 06:14 - 2017-07-14 06:14 - 00000000 ____D C:\Program Files (x86)\MSBuild
2017-07-14 06:14 - 2017-07-14 06:14 - 00000000 ____D C:\inetpub
2017-07-14 06:13 - 2017-07-14 06:13 - 01087488 _____ (Microsoft Corporation) C:\WINDOWS\system32\reseteng.dll
2017-07-14 06:13 - 2017-02-10 12:26 - 01166520 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationNative_v0300.dll
2017-07-14 06:13 - 2017-02-10 12:26 - 00124624 _____ (Microsoft Corporation) C:\WINDOWS\system32\PresentationCFFRasterizerNative_v0300.dll
2017-07-14 06:13 - 2017-02-10 12:26 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\system32\TsWpfWrp.exe
2017-07-14 06:13 - 2017-02-10 12:21 - 00778936 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationNative_v0300.dll
2017-07-14 06:13 - 2017-02-10 12:21 - 00103120 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PresentationCFFRasterizerNative_v0300.dll
2017-07-14 06:13 - 2017-02-10 12:21 - 00035480 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\TsWpfWrp.exe
2017-07-14 06:12 - 2017-07-16 19:14 - 00004166 _____ C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{DBB8FF06-B999-4A95-A7CE-15C213181723}
2017-07-14 06:12 - 2017-07-15 06:57 - 00003290 _____ C:\WINDOWS\System32\Tasks\OneDrive Standalone Update Task v2
2017-07-14 06:12 - 2017-07-14 06:12 - 00002810 _____ C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2671885098-678752524-1400920573-1001
2017-07-14 06:12 - 2017-07-14 06:12 - 00002134 _____ C:\WINDOWS\System32\Tasks\RGP Backup
2017-07-14 06:12 - 2017-07-14 06:12 - 00002118 _____ C:\WINDOWS\System32\Tasks\{39393239-4118-43A9-9EF4-579F68CFC882}
2017-07-14 06:12 - 2017-07-14 06:12 - 00001984 _____ C:\WINDOWS\System32\Tasks\{32B26120-173E-4516-BA92-CE080FB3608E}
2017-07-14 06:12 - 2017-07-14 06:12 - 00000006 ____H C:\WINDOWS\Tasks\SA.DAT
2017-07-14 06:12 - 2017-07-14 06:12 - 00000000 ____D C:\WINDOWS\System32\Tasks\OfficeSoftwareProtectionPlatform
2017-07-14 06:11 - 2017-07-14 06:12 - 00003482 _____ C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task
2017-07-14 06:11 - 2017-07-14 06:12 - 00003452 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineUA
2017-07-14 06:11 - 2017-07-14 06:12 - 00003374 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineUA1cf8dc0ce6bb10d
2017-07-14 06:11 - 2017-07-14 06:12 - 00003300 _____ C:\WINDOWS\System32\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001
2017-07-14 06:11 - 2017-07-14 06:12 - 00003228 _____ C:\WINDOWS\System32\Tasks\DropboxUpdateTaskMachineCore
2017-07-14 06:11 - 2017-07-14 06:12 - 00003204 _____ C:\WINDOWS\System32\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001
2017-07-14 06:11 - 2017-07-14 06:12 - 00003150 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d0bf681e553bf8
2017-07-14 06:11 - 2017-07-14 06:12 - 00003070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d08f601e825b6
2017-07-14 06:11 - 2017-07-14 06:12 - 00003070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore1d040ece2e11a19
2017-07-14 06:11 - 2017-07-14 06:12 - 00003070 _____ C:\WINDOWS\System32\Tasks\GoogleUpdateTaskMachineCore
2017-07-14 06:11 - 2017-07-14 06:12 - 00002816 _____ C:\WINDOWS\System32\Tasks\HPCeeScheduleForAIRWORX 2
2017-07-14 06:11 - 2017-07-14 06:12 - 00002802 _____ C:\WINDOWS\System32\Tasks\[email protected]
2017-07-14 06:11 - 2017-07-14 06:12 - 00002352 _____ C:\WINDOWS\System32\Tasks\CLVDLauncher
2017-07-14 06:11 - 2017-07-14 06:12 - 00002352 _____ C:\WINDOWS\System32\Tasks\CLMLSvc_P2G8
2017-07-14 06:11 - 2017-07-14 06:12 - 00002310 _____ C:\WINDOWS\System32\Tasks\Adobe Uninstaller
2017-07-14 06:11 - 2017-07-14 06:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Hewlett-Packard
2017-07-14 06:11 - 2017-07-14 06:11 - 00000000 ____D C:\WINDOWS\System32\Tasks\Event Viewer Tasks
2017-07-14 05:56 - 2017-07-14 05:56 - 00001519 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Media Player.lnk
2017-07-14 05:49 - 2017-07-14 05:59 - 00000000 ____D C:\WINDOWS\system32\config\bbimigrate
2017-07-14 05:47 - 2017-07-14 05:47 - 00000000 ____D C:\ProgramData\USOShared
2017-07-14 05:46 - 2017-07-17 10:14 - 00000000 ____D C:\Users\AIRWORX 2
2017-07-14 05:46 - 2017-07-14 06:05 - 00000000 ____D C:\Users\AirworxAZ
2017-07-14 05:46 - 2017-07-14 06:05 - 00000000 ____D C:\Users\Administrator
2017-07-14 05:45 - 2017-07-14 10:43 - 01004424 _____ C:\WINDOWS\system32\PerfStringBackup.INI
2017-07-14 05:44 - 2017-07-14 05:44 - 00939752 _____ C:\WINDOWS\SysWOW64\PerfStringBackup.INI
2017-07-14 05:44 - 2017-07-14 05:44 - 00000000 ____D C:\WINDOWS\SysWOW64\sda
2017-07-14 05:39 - 2017-07-14 05:39 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
2017-07-14 05:39 - 2017-07-14 05:39 - 00000000 ____D C:\Program Files\AMD
2017-07-14 05:39 - 2017-07-14 05:39 - 00000000 _____ C:\WINDOWS\ativpsrm.bin
2017-07-14 05:39 - 2017-03-18 13:56 - 02233344 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\PrintConfig.dll
2017-07-14 05:38 - 2017-07-14 05:38 - 00000000 ____H C:\WINDOWS\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
2017-07-14 05:36 - 2017-07-17 06:30 - 00000000 ____D C:\WINDOWS\system32\SleepStudy
2017-07-14 05:36 - 2017-07-14 06:00 - 00217000 _____ C:\WINDOWS\system32\FNTCACHE.DAT
2017-07-14 04:28 - 2017-07-14 04:28 - 00002103 _____ C:\Users\Public\Desktop\Adobe Reader XI.lnk
2017-07-14 03:47 - 2017-07-14 03:47 - 00251656 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klark.sys
2017-07-14 03:44 - 2017-07-14 03:44 - 00229288 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_arkmon.sys
2017-07-14 03:44 - 2017-07-14 03:44 - 00173144 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_mark.sys
2017-07-14 03:44 - 2017-07-14 03:44 - 00112912 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_klbg.sys
2017-07-14 03:44 - 2017-07-14 03:44 - 00087584 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klupd_klif_kimul.sys
2017-07-14 02:51 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Total Security
2017-07-14 02:51 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Secure Connection
2017-07-14 02:50 - 2017-04-28 15:05 - 01018592 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klif.sys
2017-07-14 02:50 - 2017-04-28 15:05 - 00197336 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\klflt.sys
2017-07-14 02:50 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\WINDOWS\system32\klfphc.dll
2017-07-14 02:37 - 2017-07-14 02:38 - 195931824 _____ (Kaspersky Lab) C:\Users\AIRWORX 2\Downloads\kts17.0.0.611abcden_12159.exe
2017-07-13 13:47 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dropbox
2017-07-12 12:58 - 2017-07-12 12:58 - 00049992 _____ (Dropbox, Inc.) C:\WINDOWS\system32\DbxSvc.exe
2017-07-12 12:58 - 2017-07-12 12:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-stable.sys
2017-07-12 12:58 - 2017-07-12 12:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-dev.sys
2017-07-12 12:58 - 2017-07-12 12:58 - 00045640 _____ (Dropbox, Inc.) C:\WINDOWS\system32\Drivers\dbx-canary.sys
2017-07-12 09:29 - 2017-07-14 08:19 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2017-07-12 09:29 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Software Updater
2017-07-12 09:29 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Security Scan
2017-07-12 09:29 - 2017-07-14 02:51 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2017-07-12 09:28 - 2017-07-14 02:39 - 00000000 ____D C:\ProgramData\Kaspersky Lab Setup Files
2017-07-12 06:53 - 2017-07-13 10:02 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-12 06:53 - 2017-07-13 08:00 - 00192216 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\MBAMSwissArmy.sys
2017-07-12 06:53 - 2017-07-13 07:59 - 00109272 _____ (Malwarebytes) C:\WINDOWS\system32\Drivers\mbamchameleon.sys
2017-07-12 06:53 - 2017-07-12 06:53 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-07-12 06:43 - 2017-07-12 16:08 - 00000512 _____ C:\Users\AIRWORX 2\Desktop\MBR.dat
2017-07-11 13:47 - 2017-07-14 06:25 - 00000000 ___DC C:\WINDOWS\Panther
2017-07-11 13:45 - 2017-07-14 09:28 - 00004565 _____ C:\VEW.txt
2017-07-11 09:24 - 2017-07-11 14:53 - 00010285 _____ C:\junk.txt
2017-07-11 05:23 - 2017-07-17 13:28 - 00000000 ____D C:\FRST
2017-07-11 04:04 - 2017-07-14 09:30 - 00028272 _____ C:\WINDOWS\system32\Drivers\TrueSight.sys
2017-07-11 04:03 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-11 04:03 - 2017-07-13 06:36 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-11 04:03 - 2017-07-11 05:12 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-10 10:51 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\LocalLow\Adobe
2017-07-10 10:51 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Adobe
2017-07-10 10:36 - 2017-07-10 10:36 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Macromedia
2017-07-10 10:31 - 2017-07-10 10:51 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Adobe
2017-07-10 10:15 - 2017-07-14 05:47 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Packages
2017-07-10 10:15 - 2017-07-10 10:15 - 00000000 ____D C:\Users\AirworxAZ\AppData\Roaming\Zeon
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\TileDataLayer
2017-07-10 10:14 - 2017-07-10 10:14 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\ConnectedDevicesPlatform
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\Documents\hp.system.package.metadata
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\Documents\hp.applications.package.appdata
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Microsoft Help
2017-07-10 10:14 - 2016-09-30 14:21 - 00000000 ____D C:\Users\AirworxAZ\AppData\Local\Google
2017-07-10 09:38 - 2017-07-14 06:51 - 00002339 _____ C:\Users\AIRWORX 2\Desktop\Google Chrome.lnk
2017-07-10 07:25 - 2017-07-10 07:25 - 00195346 _____ C:\Users\AIRWORX 2\Documents\wu170509.diagcab
2017-07-10 07:16 - 2017-07-10 07:16 - 130903960 ____C (Microsoft Corporation) C:\WINDOWS\SysWOW64\MRT.exe
2017-07-10 06:58 - 2017-07-11 10:29 - 00000214 _____ C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job
2017-07-10 04:54 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Documents\GatewaySettings.bin
2017-07-10 04:53 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Downloads\GatewaySettings.bin
2017-07-10 04:53 - 2017-07-10 04:53 - 00009804 _____ C:\Users\AIRWORX 2\Downloads\GatewaySettings (1).bin
2017-07-08 03:06 - 2017-07-08 03:06 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\GoToMeeting
2017-07-07 09:56 - 2017-07-10 06:17 - 14379154 _____ C:\Users\AIRWORX 2\Desktop\calls and txtsBook2.xlsx
2017-07-07 09:40 - 2017-07-06 14:49 - 10381776 _____ C:\Users\AIRWORX 2\Desktop\SMSBackup.xml
2017-07-07 09:40 - 2017-07-06 14:48 - 00229555 _____ C:\Users\AIRWORX 2\Desktop\CallLogBackup.xml
2017-07-07 09:34 - 2017-07-07 09:34 - 02066258 _____ C:\Users\AIRWORX 2\Downloads\Backup_Archive (1).zip
2017-07-07 09:31 - 2017-07-07 09:31 - 00190279 _____ C:\Users\AIRWORX 2\Documents\calls.txt
2017-07-07 09:29 - 2017-07-07 09:29 - 02052994 _____ C:\Users\AIRWORX 2\Downloads\Backup_20170627192522.zip
2017-07-07 09:29 - 2017-06-27 19:25 - 10333207 _____ C:\Users\AIRWORX 2\Downloads\SMSBackup.xml
2017-07-07 09:29 - 2017-06-27 19:25 - 00190279 _____ C:\Users\AIRWORX 2\Downloads\CallLogBackup.xml
2017-07-07 09:28 - 2017-07-07 09:28 - 02066258 _____ C:\Users\AIRWORX 2\Downloads\Backup_Archive.zip
2017-07-06 12:30 - 2017-07-06 12:30 - 00002603 _____ C:\Users\Public\Desktop\POS - Rock Gym Pro.lnk
2017-07-06 12:30 - 2017-07-06 12:30 - 00002603 _____ C:\Users\Public\Desktop\Data Entry - Rock Gym Pro.lnk
2017-07-06 11:46 - 2017-07-06 11:46 - 00002775 _____ C:\Users\AIRWORX 2\Downloads\images.jpeg
2017-06-30 10:07 - 2017-06-30 10:08 - 00318450 _____ C:\Users\AIRWORX 2\Documents\CallLogBackup.pdf
2017-06-29 14:34 - 2017-06-29 14:49 - 00024040 _____ C:\Users\AIRWORX 2\Documents\scan333.pdf
2017-06-29 10:44 - 2017-06-29 10:44 - 00000000 __SHD C:\found.000
2017-06-29 10:39 - 2017-06-29 10:39 - 00022330 _____ C:\Users\AIRWORX 2\Documents\support_chat_transcript_c6910346d48b4a6ea2b2f7e1f65f9d4d.txt
2017-06-29 10:02 - 2017-06-29 10:02 - 00000165 ____H C:\Users\AIRWORX 2\Documents\~$SmsBackup.xlsx
2017-06-29 10:02 - 2017-06-29 10:02 - 00000165 ____H C:\Users\AIRWORX 2\Documents\~$CallLogBackup.xlsx
2017-06-29 09:43 - 2017-06-29 09:44 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-2
2017-06-29 09:42 - 2017-06-29 09:43 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-1
2017-06-29 08:54 - 2017-06-29 09:44 - 00000000 ____D C:\CCSupport
2017-06-29 08:54 - 2017-06-29 08:55 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\.bomgartemp-d443567a9bbd939a6ce635dd5b61ef55-shl-screen_sharingcontextId-cs-0
2017-06-29 08:30 - 2017-06-29 08:31 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{3E1C46B4-AE1C-47D4-A253-B086FFB08406}
2017-06-29 08:28 - 2017-06-29 08:31 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{78ACC633-3A05-418D-841A-B650CBA92BFF}
2017-06-29 08:15 - 2017-06-29 08:15 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{A8386299-DD6B-4871-AC75-168430E1797F}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{F4796B34-AD33-4594-B511-F95371E88EEA}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{E908C560-4859-4F24-905D-9A65B1BE63E1}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{E626A012-0E1A-494A-9AB8-0870767076F6}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{89363267-36DC-427C-A99A-0AEA97994C65}
2017-06-29 08:14 - 2017-06-29 08:14 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{2A86C33F-824B-4295-8831-2FA8CE8A3C08}
2017-06-28 16:45 - 2017-07-14 06:12 - 00000372 _____ C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job
2017-06-27 16:06 - 2017-07-11 12:03 - 00000000 ____D C:\WINDOWS\pss
2017-06-27 14:40 - 2017-06-27 14:40 - 00000000 ____H C:\Users\AIRWORX 2\Documents\~WRL2295.tmp
2017-06-27 12:46 - 2017-06-27 12:55 - 00157872 _____ C:\Users\AIRWORX 2\Desktop\webmail.htm
2017-06-27 09:55 - 2017-06-27 09:55 - 01827895 _____ C:\Users\AIRWORX 2\Documents\Backup_2017-06-27 08-04-03.zip
2017-06-27 05:05 - 2017-06-27 05:05 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Belkasoft
2017-06-27 05:02 - 2017-07-14 05:59 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Belkasoft Evidence Center Ultimate
2017-06-27 05:02 - 2017-06-27 05:02 - 00002244 _____ C:\Users\Public\Desktop\Belkasoft Evidence Center Ultimate.lnk
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Passware
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Belkasoft
2017-06-27 05:02 - 2017-06-27 05:02 - 00000000 ____D C:\ProgramData\Belkasoft
2017-06-27 05:01 - 2017-06-27 05:02 - 00000000 ____D C:\Program Files (x86)\Belkasoft Evidence Center Ultimate
2017-06-26 18:44 - 2017-06-26 18:44 - 00000000 _____ C:\Users\AIRWORX 2\AppData\Local\{A5A12D5E-AE8C-4443-9C77-6230BEBDBB88}
2017-06-26 13:56 - 2017-06-26 13:57 - 44060880 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\Documents\Windows-KB890830-x64-V5.49.exe
2017-06-26 10:24 - 2017-06-26 10:25 - 06754944 _____ (ESET spol. s r.o.) C:\Users\AIRWORX 2\Documents\esetonlinescanner_enu.exe
2017-06-26 09:52 - 2017-06-28 07:52 - 00181160 _____ (ESET) C:\WINDOWS\system32\Drivers\ESETCleanersDriver.sys
2017-06-26 07:43 - 2017-07-10 06:49 - 00002065 _____ C:\Users\Public\Desktop\ESET Banking & Payment protection.lnk
2017-06-26 07:42 - 2017-07-14 05:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
2017-06-26 07:42 - 2017-06-26 07:42 - 00000000 ____D C:\ProgramData\ESET
2017-06-26 07:38 - 2017-06-26 07:40 - 120950400 _____ (ESET) C:\Users\AIRWORX 2\Documents\ess_nt64_enu.exe
2017-06-26 07:35 - 2017-06-26 07:36 - 114369664 _____ (ESET) C:\Users\AIRWORX 2\Documents\ess_nt32_enu.exe
2017-06-26 07:22 - 2017-06-26 07:22 - 00228669 _____ C:\Users\AIRWORX 2\Downloads\0,2817,2346862,00.asp
2017-06-26 07:22 - 2017-06-26 07:22 - 00165520 _____ C:\Users\AIRWORX 2\Downloads\download (2).htm
2017-06-26 07:22 - 2017-06-26 07:22 - 00029518 _____ C:\Users\AIRWORX 2\Downloads\hitmanpro.aspx
2017-06-26 07:22 - 2017-06-26 07:22 - 00005247 _____ C:\Users\AIRWORX 2\Downloads\download (3).htm
2017-06-26 07:22 - 2017-06-26 07:22 - 00000886 _____ C:\Users\AIRWORX 2\Downloads\downloadcsi.asp
2017-06-26 07:21 - 2017-06-26 07:22 - 00008705 _____ C:\Users\AIRWORX 2\Downloads\download (1).htm
2017-06-26 07:21 - 2017-06-26 07:21 - 00123745 _____ C:\Users\AIRWORX 2\Downloads\malicious-software-removal-tool-details.htm
2017-06-26 07:21 - 2017-06-26 07:21 - 00070351 _____ C:\Users\AIRWORX 2\Downloads\download.htm
2017-06-25 07:56 - 2017-06-25 07:56 - 00004425 _____ C:\Users\AIRWORX 2\Downloads\taxcard.pdf
2017-06-23 03:59 - 2017-06-23 04:10 - 381811920 _____ C:\Users\AIRWORX 2\Downloads\Photos (5).zip
2017-06-22 13:22 - 2017-06-22 13:22 - 01619628 _____ C:\Users\AIRWORX 2\Downloads\Welcome Kit_TX FIXED PRICE PRODUCT.pdf
2017-06-22 13:22 - 2017-06-22 13:22 - 00243287 _____ C:\Users\AIRWORX 2\Downloads\ENGIE Resources LLC Energy agreement with National Trampoline Entertainment Dallas LLC - 3006 - CONT24780_encrypted_.pdf
2017-06-22 12:52 - 2017-06-22 12:52 - 00204075 _____ C:\Users\AIRWORX 2\Downloads\countersigned agreement .pdf
2017-06-22 11:44 - 2017-06-22 11:44 - 00043808 _____ C:\Users\AIRWORX 2\Downloads\CCR statement as of 06 June 2017 - 95269325.pdf
2017-06-21 06:06 - 2017-06-21 06:06 - 03357542 _____ C:\Users\AIRWORX 2\Downloads\acw-dg.pdf
2017-06-20 13:52 - 2017-06-20 13:52 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\LG Electronics
2017-06-20 08:54 - 2017-06-20 08:54 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\LG Electronics
2017-06-20 08:51 - 2017-06-23 13:26 - 00000000 ____D C:\ProgramData\LGMOBILEAX
2017-06-20 08:51 - 2017-06-23 13:17 - 00002760 _____ C:\WINDOWS\SysWOW64\lgAxconfig.ini
2017-06-20 08:51 - 2017-06-20 08:51 - 04009163 _____ C:\Users\AIRWORX 2\Downloads\LG-H811M_TMO_UG_Web_EN_V1.0_151216 (1).pdf
2017-06-20 08:51 - 2011-05-06 10:37 - 00655872 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcr90.dll
2017-06-20 08:51 - 2011-05-06 10:37 - 00568832 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcp90.dll
2017-06-20 08:51 - 2011-05-06 10:37 - 00224768 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msvcm90.dll
2017-06-20 08:51 - 2006-04-30 05:33 - 00053248 _____ () C:\WINDOWS\SysWOW64\CommonDL.dll
2017-06-20 08:51 - 2005-11-19 23:34 - 00082432 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4r.dll
2017-06-20 08:51 - 2005-09-29 22:39 - 00044544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4a.dll
2017-06-20 08:51 - 2005-09-07 11:51 - 01233920 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\msxml4.dll
2017-06-20 08:47 - 2017-07-14 10:51 - 00000000 ____D C:\Program Files (x86)\LG Electronics
2017-06-17 12:29 - 2017-06-17 12:30 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Bluejay comps
2017-06-17 06:45 - 2017-06-17 06:45 - 00000000 ____D C:\Users\Public\Documents\CrashDump
 
==================== One Month Modified files and folders ========
 
(If an entry is included in the fixlist, the file/folder will be moved.)
 
2017-07-17 12:16 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\AppReadiness
2017-07-17 12:12 - 2014-03-12 15:44 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\CrashDumps
2017-07-17 03:43 - 2016-04-19 19:11 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Alarm Activity Formatted Download_files
2017-07-17 03:17 - 2017-03-18 14:01 - 00000000 ____D C:\WINDOWS\INF
2017-07-17 02:23 - 2017-03-18 14:03 - 00000000 ___HD C:\Program Files\WindowsApps
2017-07-15 06:57 - 2016-07-02 19:55 - 00002424 _____ C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\OneDrive.lnk
2017-07-15 06:57 - 2015-04-20 17:06 - 00000000 __RDO C:\Users\AIRWORX 2\OneDrive
2017-07-15 03:54 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\appcompat
2017-07-14 10:56 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\PolicyDefinitions
2017-07-14 10:56 - 2017-03-18 13:51 - 00000000 ____D C:\WINDOWS\CbsTemp
2017-07-14 10:52 - 2014-01-10 13:21 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Packages
2017-07-14 10:50 - 2013-10-14 16:33 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2017-07-14 10:47 - 2013-10-14 16:40 - 00000000 ____D C:\ProgramData\WildTangent
2017-07-14 10:47 - 2013-10-14 16:40 - 00000000 ____D C:\Program Files (x86)\WildTangent Games
2017-07-14 10:46 - 2014-08-04 13:01 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2017-07-14 10:40 - 2015-01-29 16:07 - 00000519 _____ C:\WINDOWS\system32\Drivers\etc\hosts.ics
2017-07-14 06:50 - 2017-03-18 14:03 - 00000000 ___RD C:\WINDOWS\ImmersiveControlPanel
2017-07-14 06:50 - 2016-04-26 23:39 - 00000000 __RHD C:\Users\Public\AccountPictures
2017-07-14 06:35 - 2017-03-18 14:03 - 00028672 _____ C:\WINDOWS\system32\config\BCD-Template
2017-07-14 06:32 - 2017-03-18 14:06 - 00000000 ____D C:\WINDOWS\Setup
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ___SD C:\WINDOWS\SysWOW64\F12
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ___SD C:\WINDOWS\system32\F12
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ___RD C:\Program Files\Windows Defender
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\migwiz
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\appraiser
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\ShellExperiences
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\Program Files (x86)\Windows Photo Viewer
2017-07-14 06:31 - 2017-03-18 14:03 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2017-07-14 06:29 - 2013-10-14 16:36 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Music, Photos and Videos
2017-07-14 06:29 - 2013-10-14 16:36 - 00000000 ____D C:\Program Files\IDT
2017-07-14 06:28 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\rescache
2017-07-14 06:24 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\WinBioDatabase
2017-07-14 06:23 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\Dism
2017-07-14 06:23 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\WinBioPlugIns
2017-07-14 06:23 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\Provisioning
2017-07-14 06:23 - 2017-03-18 04:40 - 00000000 ____D C:\WINDOWS\system32\Dism
2017-07-14 06:19 - 2016-07-16 04:47 - 00000000 ____D C:\WINDOWS\system32\Tasks_Migrated
2017-07-14 06:18 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\Registration
2017-07-14 06:14 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\inetsrv
2017-07-14 06:14 - 2017-03-18 13:59 - 00204800 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisRtl.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00172544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisRtl.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00054272 _____ (Microsoft Corporation) C:\WINDOWS\system32\admwprox.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00053248 _____ (Microsoft Corporation) C:\WINDOWS\system32\ahadmin.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00049664 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\admwprox.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00026112 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\ahadmin.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00019456 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisreset.exe
2017-07-14 06:14 - 2017-03-18 13:59 - 00016896 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisreset.exe
2017-07-14 06:14 - 2017-03-18 13:59 - 00015360 _____ (Microsoft Corporation) C:\WINDOWS\system32\wamregps.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00014336 _____ (Microsoft Corporation) C:\WINDOWS\system32\cngkeyhelper.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00013312 _____ (Microsoft Corporation) C:\WINDOWS\system32\iisrstap.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wamregps.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00011264 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\cngkeyhelper.dll
2017-07-14 06:14 - 2017-03-18 13:59 - 00010240 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\iisrstap.dll
2017-07-14 06:12 - 2017-03-18 19:31 - 00000000 ____D C:\WINDOWS\HoloShell
2017-07-14 06:12 - 2014-10-29 11:58 - 00022840 _____ C:\WINDOWS\system32\emptyregdb.dat
2017-07-14 06:11 - 2017-03-18 14:03 - 00000000 __RHD C:\Users\Public\Libraries
2017-07-14 06:04 - 2014-07-02 11:24 - 00002279 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2017-07-14 06:02 - 2017-03-18 14:03 - 00000000 ____D C:\ProgramData\regid.1991-06.com.microsoft
2017-07-14 05:59 - 2017-06-13 19:20 - 00000000 ____D C:\WINDOWS\system32\UNP
2017-07-14 05:59 - 2017-05-10 18:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shutterfly Uploader
2017-07-14 05:59 - 2017-05-03 08:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Family Lawyer
2017-07-14 05:59 - 2017-04-21 05:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Cox Cloud Drive
2017-07-14 05:59 - 2017-04-05 05:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DB Browser for SQLite
2017-07-14 05:59 - 2017-03-18 14:03 - 00000000 ___SD C:\WINDOWS\Downloaded Program Files
2017-07-14 05:59 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\FxsTmp
2017-07-14 05:59 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\ModemLogs
2017-07-14 05:59 - 2017-03-18 04:40 - 00786432 _____ C:\WINDOWS\system32\config\BBI
2017-07-14 05:59 - 2017-03-18 04:40 - 00008192 _____ C:\WINDOWS\system32\config\ELAM
2017-07-14 05:59 - 2017-03-17 14:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Escaperoom Software
2017-07-14 05:59 - 2017-03-16 15:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Drive
2017-07-14 05:59 - 2017-02-20 09:27 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Verizon
2017-07-14 05:59 - 2017-02-20 09:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Recuva
2017-07-14 05:59 - 2017-01-03 09:39 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dahuatech Smart Player
2017-07-14 05:59 - 2016-12-21 09:20 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2017-07-14 05:59 - 2016-10-27 03:53 - 00000000 ____D C:\WINDOWS\system32\nn-NO
2017-07-14 05:59 - 2016-09-30 14:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
2017-07-14 05:59 - 2016-07-01 17:30 - 00065536 _____ C:\WINDOWS\system32\spu_storage.bin
2017-07-14 05:59 - 2016-05-12 20:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Fitbit Connect
2017-07-14 05:59 - 2016-04-28 08:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
2017-07-14 05:59 - 2016-04-26 23:20 - 00000000 ____D C:\WINDOWS\ShellNew
2017-07-14 05:59 - 2016-02-09 09:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TaxAct
2017-07-14 05:59 - 2015-06-08 09:43 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java
2017-07-14 05:59 - 2015-04-03 17:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Brother
2017-07-14 05:59 - 2014-12-30 17:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVIGenerator2.0
2017-07-14 05:59 - 2014-06-19 09:37 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SurveillanceSystem
2017-07-14 05:59 - 2014-04-18 14:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASAP Utilities
2017-07-14 05:59 - 2014-03-13 16:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Epson Software
2017-07-14 05:59 - 2014-03-13 16:36 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Scan
2017-07-14 05:59 - 2014-03-12 15:27 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PDF Create 7
2017-07-14 05:59 - 2014-03-12 15:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nuance PaperPort 14
2017-07-14 05:59 - 2014-03-04 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2017-07-14 05:59 - 2014-03-04 13:30 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rock Gym Pro
2017-07-14 05:59 - 2013-10-14 16:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Productivity and Tools
2017-07-14 05:59 - 2013-10-14 16:40 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2017-07-14 05:59 - 2013-10-14 16:34 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP Help and Support
2017-07-14 05:56 - 2015-10-29 23:28 - 00000000 ____D C:\Users\Default.migrated
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lv-LV
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\lt-LT
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\IME
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\et-EE
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\en-GB
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\spool
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\oobe
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\NDF
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\lv-LV
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\lt-LT
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\InputMethod
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\IME
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\et-EE
2017-07-14 05:52 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\system32\en-GB
2017-07-14 05:52 - 2016-09-30 14:07 - 00000000 ____D C:\WINDOWS\system32\SRSLabs
2017-07-14 05:52 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Shared
2017-07-14 05:52 - 2013-08-22 08:36 - 00000000 ____D C:\WINDOWS\system32\WindowsInternal.Inbox.Media.Shared
2017-07-14 05:51 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\LiveKernelReports
2017-07-14 05:51 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\InputMethod
2017-07-14 05:51 - 2016-02-04 13:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Western Digital
2017-07-14 05:51 - 2014-03-04 12:07 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Shopping and Services
2017-07-14 05:50 - 2017-05-31 09:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
2017-07-14 05:50 - 2017-03-18 14:03 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2017-07-14 05:50 - 2016-03-03 12:25 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Seagate
2017-07-14 05:50 - 2014-03-13 16:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON
2017-07-14 05:50 - 2014-03-04 13:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MySQL
2017-07-14 05:50 - 2013-10-14 16:53 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Communication and Chat
2017-07-14 05:50 - 2013-10-14 16:38 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Security and Protection
2017-07-14 05:49 - 2017-03-18 14:03 - 00000000 ____D C:\WINDOWS\SysWOW64\inetsrv
2017-07-14 05:49 - 2013-08-22 08:36 - 00000000 ___HD C:\WINDOWS\system32\GroupPolicy
2017-07-14 05:47 - 2017-03-18 14:03 - 00000000 ____D C:\ProgramData\USOPrivate
2017-07-14 05:46 - 2013-04-03 17:13 - 00000000 ____D C:\Users\Administrator\AppData\Local\Packages
2017-07-14 05:44 - 2017-03-18 04:40 - 00000000 ____D C:\WINDOWS\system32\Sysprep
2017-07-14 04:54 - 2017-03-18 20:20 - 00000000 ___HD C:\$WINDOWS.~BT
2017-07-14 04:28 - 2017-01-24 15:31 - 00002457 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2017-07-14 04:28 - 2014-03-04 16:20 - 00000000 ____D C:\ProgramData\Adobe
2017-07-14 03:46 - 2016-06-14 17:47 - 00199392 _____ (AO Kaspersky Lab) C:\WINDOWS\system32\Drivers\kneps.sys
2017-07-14 03:44 - 2015-11-12 07:03 - 00000000 ____D C:\Program Files\Common Files\AV
2017-07-13 13:48 - 2015-10-19 12:01 - 00000000 ____D C:\Program Files (x86)\Dropbox
2017-07-12 02:21 - 2016-03-08 09:58 - 00000000 ____D C:\Users\AIRWORX 2\Documents\Outlook Files
2017-07-12 02:21 - 2015-07-30 12:30 - 00525312 _____ C:\Users\AIRWORX 2\Outlook.pst
2017-07-11 14:08 - 2014-03-06 03:09 - 00000000 ____D C:\WINDOWS\system32\MRT
2017-07-11 14:04 - 2014-03-06 03:09 - 135225752 ____C (Microsoft Corporation) C:\WINDOWS\system32\MRT.exe
2017-07-11 12:11 - 2017-06-13 19:20 - 00000000 ____D C:\Program Files\UNP
2017-07-11 12:05 - 2015-07-13 07:14 - 00132848 _____ (ESET) C:\WINDOWS\system32\Drivers\eamonm.sys
2017-07-11 10:24 - 2014-04-18 14:27 - 00000000 ____D C:\Program Files (x86)\ASAP Utilities
2017-07-11 05:16 - 2015-01-29 18:03 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\ElevatedDiagnostics
2017-07-10 15:47 - 2014-03-26 16:20 - 00000000 ___RD C:\Users\AIRWORX 2\Dropbox
2017-07-10 15:42 - 2017-06-16 12:04 - 00000000 ____D C:\Users\AIRWORX 2\Desktop\Babe
2017-07-10 10:26 - 2017-02-16 07:35 - 00000000 ____D C:\Program Files (x86)\Wondershare
2017-07-10 06:42 - 2016-07-01 14:24 - 00000000 ____D C:\Windows10Upgrade
2017-07-10 06:30 - 2015-09-07 08:21 - 00000678 _____ C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001.job
2017-07-10 06:30 - 2014-04-02 13:11 - 00000582 _____ C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001.job
2017-07-07 10:46 - 2015-12-14 11:13 - 00113371 _____ C:\Users\AIRWORX 2\Desktop\Book2.xlsx
2017-07-06 12:30 - 2014-10-23 16:52 - 00002603 _____ C:\Users\Public\Desktop\Calendar - Rock Gym Pro.lnk
2017-07-06 12:30 - 2014-03-04 13:30 - 00002603 _____ C:\Users\Public\Desktop\CheckIn - Rock Gym Pro.lnk
2017-07-06 12:30 - 2014-03-04 13:30 - 00000000 ____D C:\Program Files (x86)\Rock Gym Pro
2017-07-03 15:52 - 2017-02-20 08:22 - 00000000 ____D C:\Program Files\Recuva
2017-07-03 15:04 - 2016-10-27 13:08 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\ThisLife
2017-06-30 07:47 - 2017-03-18 14:06 - 00835576 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe
2017-06-30 07:47 - 2017-03-18 14:06 - 00177656 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl
2017-06-29 14:49 - 2017-02-10 07:53 - 00003072 ___SH C:\Users\AIRWORX 2\Documents\PPMetaData.bin
2017-06-29 14:49 - 2014-03-26 13:01 - 00311230 ____H C:\Users\AIRWORX 2\Documents\.ppinfocache
2017-06-29 14:49 - 2014-03-26 12:59 - 00042262 ____H C:\Users\AIRWORX 2\Documents\PP11Thumbs.ptn2
2017-06-29 14:49 - 2014-03-26 12:59 - 00026319 ____H C:\Users\AIRWORX 2\Documents\maxdesk.ini2
2017-06-29 14:49 - 2014-03-26 12:57 - 33680638 ____H C:\Users\AIRWORX 2\Documents\PP11Thumbs.ptn
2017-06-29 14:49 - 2014-03-12 15:25 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\.oit
2017-06-28 02:52 - 2014-12-23 11:08 - 00000000 ____D C:\Program Files\ESET
2017-06-26 10:25 - 2014-03-04 13:12 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\ESET
2017-06-26 10:07 - 2014-03-04 13:12 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\ESET
2017-06-26 07:02 - 2014-12-30 17:01 - 00000000 ____D C:\Program Files (x86)\Video Client
2017-06-26 07:01 - 2013-10-14 16:54 - 00000000 ____D C:\Program Files (x86)\Windows Live
2017-06-26 06:59 - 2014-03-27 12:37 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Windows Live
2017-06-26 06:58 - 2017-05-31 09:35 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Roaming\Samsung
2017-06-26 06:58 - 2017-05-31 09:35 - 00000000 ____D C:\Program Files (x86)\Samsung
2017-06-25 10:19 - 2014-05-28 14:16 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Google
2017-06-24 00:35 - 2017-02-16 09:34 - 00000000 ___HD C:\DrFoneForAndroid
2017-06-23 16:07 - 2014-03-20 11:21 - 00000000 ____D C:\ProgramData\WebEx
2017-06-23 16:07 - 2013-10-14 16:40 - 00000000 ____D C:\ProgramData\Apple
2017-06-23 16:06 - 2014-04-02 13:10 - 00000000 ____D C:\Users\AIRWORX 2\AppData\Local\Citrix
2017-06-23 16:06 - 2014-03-11 15:49 - 00000000 ____D C:\Program Files (x86)\epson
 
==================== Files in the root of some directories =======
 
2015-04-01 09:26 - 2005-12-08 19:51 - 0000060 ____R () C:\Program Files (x86)\BRINST.INI
2017-04-14 06:58 - 2017-04-14 06:58 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Roaming\IVOPEN.$$$
2014-12-17 10:09 - 2014-12-17 10:10 - 0012962 _____ () C:\Users\AIRWORX 2\AppData\Roaming\Microsoft Excel 97-2003.CAL
2014-03-26 13:47 - 2017-05-22 04:36 - 0007607 _____ () C:\Users\AIRWORX 2\AppData\Local\resmon.resmoncfg
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{2A86C33F-824B-4295-8831-2FA8CE8A3C08}
2017-06-29 08:30 - 2017-06-29 08:31 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{3E1C46B4-AE1C-47D4-A253-B086FFB08406}
2017-06-29 08:28 - 2017-06-29 08:31 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{78ACC633-3A05-418D-841A-B650CBA92BFF}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{89363267-36DC-427C-A99A-0AEA97994C65}
2017-06-26 18:44 - 2017-06-26 18:44 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{A5A12D5E-AE8C-4443-9C77-6230BEBDBB88}
2017-06-29 08:15 - 2017-06-29 08:15 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{A8386299-DD6B-4871-AC75-168430E1797F}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{E626A012-0E1A-494A-9AB8-0870767076F6}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{E908C560-4859-4F24-905D-9A65B1BE63E1}
2017-06-29 08:14 - 2017-06-29 08:14 - 0000000 _____ () C:\Users\AIRWORX 2\AppData\Local\{F4796B34-AD33-4594-B511-F95371E88EEA}
2015-12-09 12:34 - 2015-12-09 12:34 - 0000145 _____ () C:\ProgramData\Microsoft.SqlServer.Compact.351.64.bc
2014-03-24 15:02 - 2014-10-23 13:06 - 0000226 _____ () C:\ProgramData\RSUserCfg.ini
2017-07-14 10:46 - 2012-10-24 12:44 - 0656048 _____ (WildTangent, Inc.) C:\ProgramData\uninstall2810124.exe
 
Files to move or delete:
====================
C:\Program Files (x86)\Cox\Drag and Drop Backup\vewatch.exe
C:\Users\AIRWORX 2\ASAP_Utilities_5-2-1_HS_Setup.exe
C:\Users\AIRWORX 2\WDMyCloud_win.exe
C:\ProgramData\uninstall2810124.exe
 
 
Some files in TEMP:
====================
2017-07-14 09:29 - 2017-07-14 06:30 - 1930320 _____ (Microsoft Corporation) C:\Users\AIRWORX 2\AppData\Local\Temp\dllnt_dump.dll
 
==================== Bamital & volsnap ======================
 
(There is no automatic fix for files that do not pass verification.)
 
C:\WINDOWS\system32\winlogon.exe => File is digitally signed
C:\WINDOWS\system32\wininit.exe => File is digitally signed
C:\WINDOWS\explorer.exe => File is digitally signed
C:\WINDOWS\SysWOW64\explorer.exe => File is digitally signed
C:\WINDOWS\system32\svchost.exe => File is digitally signed
C:\WINDOWS\SysWOW64\svchost.exe => File is digitally signed
C:\WINDOWS\system32\services.exe => File is digitally signed
C:\WINDOWS\system32\User32.dll => File is digitally signed
C:\WINDOWS\SysWOW64\User32.dll => File is digitally signed
C:\WINDOWS\system32\userinit.exe => File is digitally signed
C:\WINDOWS\SysWOW64\userinit.exe => File is digitally signed
C:\WINDOWS\system32\rpcss.dll => File is digitally signed
C:\WINDOWS\system32\dnsapi.dll => File is digitally signed
C:\WINDOWS\SysWOW64\dnsapi.dll => File is digitally signed
C:\WINDOWS\system32\Drivers\volsnap.sys => File is digitally signed
 
LastRegBack: 2017-07-14 05:36
 
==================== End of FRST.txt ============================

 

 

 

 

 

 

 

 

 

 

 

 

Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-07-2017
Ran by AIRWORX 2 (17-07-2017 13:32:01)
Running from C:\Users\AIRWORX 2\Desktop\Cleanup apps
Windows 10 Home Version 1703 (X64) (2017-07-14 13:25:55)
Boot Mode: Normal
==========================================================
 
 
==================== Accounts: =============================
 
Administrator (S-1-5-21-2671885098-678752524-1400920573-500 - Administrator - Disabled) => C:\Users\Administrator
AIRWORX 2 (S-1-5-21-2671885098-678752524-1400920573-1001 - Administrator - Enabled) => C:\Users\AIRWORX 2
AirworxAZ (S-1-5-21-2671885098-678752524-1400920573-1007 - Administrator - Enabled) => C:\Users\AirworxAZ
DefaultAccount (S-1-5-21-2671885098-678752524-1400920573-503 - Limited - Disabled)
Guest (S-1-5-21-2671885098-678752524-1400920573-501 - Limited - Disabled)
 
==================== Security Center ========================
 
(If an entry is included in the fixlist, it will be removed.)
 
AV: Kaspersky Total Security (Disabled - Up to date) {86367591-4BE4-AE08-2FD9-7FCB8259CD98}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AV: ESET Smart Security (Enabled - Up to date) {EC1D6F37-E411-475A-DF50-12FF7FE4AC70}
AS: ESET Smart Security (Enabled - Up to date) {577C8ED3-C22B-48D4-E5E0-298D0463E6CD}
AS: Kaspersky Total Security (Disabled - Up to date) {3D579475-6DDE-A186-1569-44B9F9DE8725}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ESET Personal firewall (Disabled) {D426EE12-AE7E-4602-F40F-BBCA8137EB0B}
FW: Kaspersky Total Security (Disabled) {BE0DF4B4-018B-AF50-0486-D6FE7C8A8AE3}
 
==================== Installed Programs ======================
 
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
 
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Photoshop Elements 4.0 (HKLM-x32\...\Adobe Photoshop Elements 4) (Version: 4.0 - Adobe Systems Inc.)
Adobe Reader XI (11.0.10) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\{05E5AD66-7CD0-4719-A229-0D3A7A5240D2}) (Version: 20.22.2217.13862 - Alcor Micro Corp.) Hidden
Alcor Micro USB Card Reader Driver  (HKLM-x32\...\AmUStor) (Version: 20.22.2217.13862 - Alcor Micro Corp.)
AMD Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
AMD Catalyst Install Manager (HKLM\...\{40959651-122E-1A16-9011-40629C01703F}) (Version: 8.0.911.0 - Advanced Micro Devices, Inc.)
ASAP Utilities (HKLM-x32\...\ASAP Utilities_is1) (Version: 7.1 - Bastien Mensink - A Must in Every Office BV)
AVIGenerator2.0 2.0.0.3 (HKLM-x32\...\AVIGenerator2.0) (Version: 2.0.0.3 - )
Belkasoft Evidence Center Ultimate (HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\Belkasoft Evidence Center Ultimate) (Version:  - )
Broderbund Family Lawyer (HKLM-x32\...\{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}) (Version: 1.00.0000 - Bluecase) Hidden
Broderbund Family Lawyer (HKLM-x32\...\InstallShield_{ED95E1BA-8C35-4D78-8A20-FD5A728711E2}) (Version: 1.00.0000 - Bluecase)
Brother MFL-Pro Suite MFC-7860DW (HKLM-x32\...\{3ACCCFB3-7B17-4E9F-ACB0-46868FCD4487}) (Version: 1.1.3.0 - Brother Industries, Ltd.)
Cloud Drive (HKLM-x32\...\{F40EC703-6B64-4C2D-80BC-5ED2D8295C04}) (Version: 5.1.30.18 - Cox Secure Online Backup for Windows)
CMS (HKLM-x32\...\{2A0DCCF2-C699-4445-BFAD-888EC538EB7F}) (Version: 3.51.1.8 - )
CyberLink Media Suite 10 (HKLM-x32\...\InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}) (Version: 10.0.4.3003 - CyberLink Corp.)
Cyberlink PhotoDirector (HKLM-x32\...\InstallShield_{39337565-330E-4ab6-A9AE-AC81E0720B10}) (Version: 3.0.3.4608 - CyberLink Corp.)
CyberLink Power2Go 8 (HKLM-x32\...\InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}) (Version: 8.0.4.2921 - CyberLink Corp.)
CyberLink PowerDirector 10 (HKLM-x32\...\InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}) (Version: 10.0.4.3007 - CyberLink Corp.)
DB Browser for SQLite (HKLM-x32\...\DB Browser for SQLite) (Version: 3.9.1 - DB Browser for SQLite Team)
Drag and Drop Backup (HKLM-x32\...\{480EA68A-699D-450D-9869-2216AC49D23C}) (Version: 2.1.33 - Cox)
Dropbox (HKLM-x32\...\Dropbox) (Version: 30.4.22 - Dropbox, Inc.)
Dropbox Update Helper (HKLM-x32\...\{099218A5-A723-43DC-8DB5-6173656A1E94}) (Version: 1.3.59.1 - Dropbox, Inc.) Hidden
Epson Copy Utility 3.5 (HKLM-x32\...\{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}) (Version: 3.5.0.0 - )
Epson Event Manager (HKLM-x32\...\{48F22622-1CC2-4A83-9C1E-644DD96F832D}) (Version: 2.30.01 - SEIKO EPSON Corporation)
EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version:  - )
Escaperoom Software (HKLM-x32\...\{7BAA7E0D-9B92-4FE7-AEC8-F11EAE801922}) (Version: 3.1.0.0 - Escaperoom Software)
ESET Smart Security (HKLM\...\{2B587448-4CE3-4196-A237-A425E557F052}) (Version: 10.1.204.0 - ESET, spol. s r.o.)
Fitbit Connect (HKLM-x32\...\{6EB73D9D-645E-415B-8008-83C3CB865968}) (Version: 2.0.1.6742 - Fitbit Inc.)
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 59.0.3071.115 - Google Inc.)
Google Drive (HKLM-x32\...\{A1238426-ECDF-4639-BE2F-8D12A97AE23C}) (Version: 2.34.5075.1619 - Google, Inc.)
Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.5 - Google Inc.) Hidden
Google Update Helper (HKLM-x32\...\{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}) (Version: 1.3.25.11 - Google Inc.) Hidden
Hewlett-Packard ACLM.NET v1.2.2.1 (HKLM-x32\...\{6F340107-F9AA-47C6-B54C-C3A19F11553F}) (Version: 1.00.0000 - Hewlett-Packard Company) Hidden
HP Quick Start (HKLM-x32\...\{574F0207-8E98-46CD-8F79-318348C98C46}) (Version: 1.0.4660.30220 - Hewlett-Packard)
HP Registration Service (HKLM\...\{D1E8F2D7-7794-4245-B286-87ED86C1893C}) (Version: 1.2.6668.4491 - Hewlett-Packard)
HP Support Assistant (HKLM-x32\...\{79C54A05-F146-4EA0-8A70-D4EFE6181E52}) (Version: 8.4.19.3 - Hewlett-Packard Company)
HP Support Information (HKLM-x32\...\{B2B7B1C8-7C8B-476C-BE2C-049731C55992}) (Version: 12.00.0000 - Hewlett-Packard)
HP Support Solutions Framework (HKLM-x32\...\{E2CB09C1-3C76-4395-BB47-50C066535CF8}) (Version: 12.7.27.15 - HP)
IDT Audio (HKLM-x32\...\{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}) (Version: 1.0.6482.0 - IDT)
Java 8 Update 131 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F32180131F0}) (Version: 8.0.1310.11 - Oracle Corporation)
Kaspersky Secure Connection (HKLM-x32\...\{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Secure Connection (HKLM-x32\...\InstallWIX_{1CF84962-50F8-48CA-9082-B70F3A02C686}) (Version: 17.0.0.611 - Kaspersky Lab)
Kaspersky Security Scan (HKLM-x32\...\{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab) Hidden
Kaspersky Security Scan (HKLM-x32\...\InstallWIX_{D1282694-0693-41A8-ABC1-6D1FFC1F65C5}) (Version: 16.0.0.1344 - Kaspersky Lab)
Kaspersky Software Updater (HKLM-x32\...\{DEEDA858-A9B4-4212-8873-2F2CE2706E68}) (Version: 2.0.0.623 - Kaspersky Lab) Hidden
Kaspersky Software Updater (HKLM-x32\...\InstallWIX_{DEEDA858-A9B4-4212-8873-2F2CE2706E68}) (Version: 2.0.0.623 - Kaspersky Lab)
Kaspersky Total Security (HKLM-x32\...\{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab) Hidden
Kaspersky Total Security (HKLM-x32\...\InstallWIX_{E27B1D7B-3B34-43A2-9FC0-9828D5DF46E2}) (Version: 17.0.0.611 - Kaspersky Lab)
Microsoft Office Professional 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\OneDriveSetup.exe) (Version: 17.3.6917.0607 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.50907.0 - Microsoft Corporation)
Microsoft SkyDrive (HKU\S-1-5-21-2671885098-678752524-1400920573-500\...\SkyDriveSetup.exe) (Version: 16.4.6013.0910 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4048 (HKLM\...\{91415F19-4C22-3609-A105-92ED3522D83C}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4048 (HKLM-x32\...\{5B1F2843-B379-3FF2-B0D3-64DD143ED53A}) (Version: 9.0.30729.4048 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.61030 (HKLM-x32\...\{ca67548a-5ebe-413a-b50c-4b9ceb6d66c6}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM-x32\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.30501 (HKLM-x32\...\{f65db027-aff3-4070-886a-0d87064aabb1}) (Version: 12.0.30501.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23918 (HKLM-x32\...\{dab68466-3a7d-41a8-a5cf-415e3ff8ef71}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual C++ 2015 Redistributable (x86) - 14.0.23918 (HKLM-x32\...\{2e085fd2-a3e4-4b39-8e10-6b8d35f55244}) (Version: 14.0.23918.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x64) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x64)) (Version: 10.0.50903 - Microsoft Corporation)
MsBackupViewer (HKLM-x32\...\{EA75EA52-124B-4A5D-994C-87DD4428DEF9}) (Version: 6.1.2.1 - )
MySQL Connector/ODBC 5.1 (HKLM-x32\...\{38CDEC3E-ABC4-4EB8-BE3B-2181A97813AE}) (Version: 5.1.12 - Oracle Corporation)
MySQL Server 5.0 (HKLM-x32\...\{97EFE060-CE35-4709-9B3A-5D3C8F686FED}) (Version: 5.0.90 - MySQL AB)
Nuance PaperPort 14 (HKLM-x32\...\{14CB3B82-FBDC-4462-919E-86147983F09B}) (Version: 14.5.0000 - Nuance Communications, Inc.)
Nuance PDF Create 7 (HKLM\...\{AAA715B7-02F9-4F2D-92C9-80EC63835AA1}) (Version: 7.10.6408 - Nuance Communications, Inc.)
Nuance PDF Create 7 (HKLM-x32\...\{AAA715B7-02F9-4F2D-92C9-80EC63835AA1}) (Version: 7.10.6408 - Nuance Communications, Inc.)
Nuance PDF Viewer Plus (HKLM-x32\...\{FC984E39-43D0-4AB2-ACC7-A7B87977B009}) (Version: 7.20.3274 - Nuance Communications, Inc.)
PaperPort Image Printer 64-bit (HKLM\...\{715CAACC-579B-4831-A5F4-A83A8DE3EFE2}) (Version: 14.00.0001 - Nuance Communications, Inc.)
Pinger (HKLM-x32\...\{9B56B031-A6C0-4BB7-8F61-938548C1B759}) (Version: 1.1.1.2 - Pinger Inc.) Hidden
Pinger (HKLM-x32\...\Pinger 1.1.1.2) (Version: 1.1.1.2 - Pinger Inc.)
Qualcomm Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Qualcomm Atheros)
Realtek Card Reader (HKLM-x32\...\{5BC2B5AB-80DE-4E83-B8CF-426902051D0A}) (Version: 10.0.10125.31214 - Realtek Semiconductor Corp.)
Recovery Manager (HKLM-x32\...\{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}) (Version: 5.5.0.6208 - CyberLink Corp.) Hidden
Recuva (HKLM\...\Recuva) (Version: 1.53 - Piriform)
Rock Gym Pro (HKLM-x32\...\{827570FB-0E88-444C-ADBC-9E799571E292}) (Version: 1.1.21247 - RGP Development LLC)
RogueKiller version 12.11.6.0 (HKLM\...\8B3D7924-ED89-486B-8322-E8594065D5CB_is1) (Version: 12.11.6.0 - Adlice Software)
Samsung USB Driver for Mobile Phones (HKLM\...\{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}) (Version: 1.5.63.0 - Samsung Electronics Co., Ltd.)
Scansoft PDF Create (HKLM-x32\...\{068724F8-D8BE-4B43-8DDD-B9FE9E49FD76}) (Version:  - ) Hidden
Seagate DiscWizard (HKLM-x32\...\{8FB2A014-A0B0-42D8-8E18-9AFC6A6E2814}) (Version: 13.0.14387 - Seagate)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM-x32\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version:  - Microsoft)
Shutterfly Uploader (HKLM-x32\...\{CD928A00-1C70-4353-B9B9-7BC8600F3E43}) (Version: 2.9.0.737 - Shutterfly, Inc.)
Smart Player (HKLM-x32\...\Smart Player3.00.0) (Version: 3.00.0 - Zhejiang Dahua Technology Co.,LTD.)
Smart Switch (HKLM-x32\...\{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17054.16 - Samsung Electronics Co., Ltd.) Hidden
Smart Switch (HKLM-x32\...\InstallShield_{74FA5314-85C8-4E2A-907D-D9ECCCB770A7}) (Version: 4.1.17054.16 - Samsung Electronics Co., Ltd.)
SyncFileSetup (x86) (HKLM-x32\...\{04848A0A-02B1-4703-B15D-6E7DCF95FB84}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc) Hidden
TaxAct 2015 1040 Edition (HKLM-x32\...\TaxAct 2015 1040 Edition) (Version: 1.03 - TaxAct, Inc.)
TaxAct 2015 Arizona (HKLM-x32\...\TaxAct 2015 Arizona) (Version: 1.02 - TaxAct, Inc.)
TaxAct 2016 1040 Edition (HKLM-x32\...\TaxAct 2016 1040 Edition) (Version: 1.03 - TaxAct, Inc.)
Verizon Wireless Software Utility Application for Android - Samsung (HKLM-x32\...\{69258FD1-F4EE-475A-83D1-BF68C8029592}) (Version: 2.14.0402 - Samsung Electronics Co., Ltd.)
WD Sync (HKLM-x32\...\{0d591303-bbc5-4645-a03b-1c3f75f1a762}) (Version: 1.3.5949.26210 - Western Digital Technologies, Inc.)
Windows 10 Update and Privacy Settings (HKLM\...\{4DFCD818-036A-4229-A67D-CF17DC461D92}) (Version: 1.0.14.0 - Microsoft Corporation)
Windows 10 Upgrade Assistant (HKLM-x32\...\{D5C69738-B486-402E-85AC-2456D98A64E4}) (Version: 1.4.9200.17332 - Microsoft Corporation)
WorkForce GT-1500 Scanner Driver Update (HKLM-x32\...\{37D0F29D-AB95-4598-ACF0-D3CC38C161D9}) (Version:  - )
 
==================== Custom CLSID (Whitelisted): ==========================
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
CustomCLSID: HKU\S-1-5-21-2671885098-678752524-1400920573-1001_Classes\CLSID\{162C6FB5-44D3-435B-903D-E613FA093FB5}\InprocServer32 -> C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6390.0509\amd64\FileCoAuthLib64.dll => No File
CustomCLSID: HKU\S-1-5-21-2671885098-678752524-1400920573-1001_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\1350\G2MOutlookAddin64.dll => No File
CustomCLSID: HKU\S-1-5-21-2671885098-678752524-1400920573-1001_Classes\CLSID\{F8071786-1FD0-4A66-81A1-3CBE29274458}\InprocServer32 -> C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\amd64\FileSyncApi64.dll => No File
ShellIconOverlayIdentifiers: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers: [  GoogleDriveBlacklisted] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D42} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSynced] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D40} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers: [  GoogleDriveSyncing] -> {81539FE6-33C7-4CE7-90C7-1C7B8F2F2D41} => C:\Program Files (x86)\Google\Drive\googledrivesync64.dll [2017-03-21] (Google)
ShellIconOverlayIdentifiers-x32: [   DropboxExt01] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt02] -> {FB314EDF-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt03] -> {FB314EE1-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt04] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt05] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt06] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt07] -> {FB314EDD-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt08] -> {FB314EE0-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt09] -> {FB314EE2-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [   DropboxExt10] -> {FB314EDE-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [ OneDrive1] -> {BBACC218-34EA-4666-9D7A-C78F2274A524} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive2] -> {5AB7172C-9C11-405C-8DD5-AF20F3606282} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive3] -> {A78ED123-AB77-406B-9962-2A5D9D2F7F30} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive4] -> {F241C880-6982-4CE5-8CF7-7085BA96DA5A} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive5] -> {A0396A93-DC06-4AEF-BEE9-95FFCCAEF20E} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [ OneDrive6] -> {9AA2F32D-362A-42D9-9328-24A483E2CCC3} => C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\17.3.6743.1212\FileSyncShell.dll -> No File
ShellIconOverlayIdentifiers-x32: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ShellIconOverlayIdentifiers-x32: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} => C:\Program Files (x86)\Dropbox\Client\DropboxExt.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers01: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers01: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2013-05-24] (Cyberlink)
ContextMenuHandlers01: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers01: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-07-11] (ESET)
ContextMenuHandlers01: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers01: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\shellex.dll [2017-04-28] (AO Kaspersky Lab)
ContextMenuHandlers01: [WDSyncContextMenuHandler] -> {5A51BDCB-F8C2-4698-B79C-A77DF0AA466B} => C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation)
ContextMenuHandlers01: [Zeon.MFCDirectShellExt] -> {353C642C-F13D-4699-9FF2-EFAF490B6C69} => C:\Program Files (x86)\Nuance\PDFCreate\bin\DirectShellExt.dll [2010-07-16] (Zeon International Investment Corp. )
ContextMenuHandlers02: [CLVDShellExt] -> {3E2A0A32-6E14-4BAD-AA87-BBB6A75EBFF2} => C:\Program Files (x86)\Common Files\CyberLink\ShellExtComponent\CLVDShellExt.dll [2013-05-24] (Cyberlink)
ContextMenuHandlers02: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-07-11] (ESET)
ContextMenuHandlers02: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\shellex.dll [2017-04-28] (AO Kaspersky Lab)
ContextMenuHandlers04: [7-Zip] -> {23170F69-40C1-278A-1000-000100020000} => C:\Program Files\7-Zip\7-zip.dll [2010-11-18] (Igor Pavlov)
ContextMenuHandlers04: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers04: [GDContextMenu] -> {BB02B294-8425-42E5-983F-41A1FA970CD6} => C:\Program Files (x86)\Google\Drive\contextmenu64.dll [2017-03-21] (Google)
ContextMenuHandlers04: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\shellex.dll [2017-04-28] (AO Kaspersky Lab)
ContextMenuHandlers04: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers05: [ACE] -> {5E2121EE-0300-11D4-8D3B-444553540000} => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\atiacm64.dll [2015-11-04] (Advanced Micro Devices, Inc.)
ContextMenuHandlers05: [DropboxExt] -> {ECD97DE5-3C8F-4ACB-AEEE-CCAB78F7711C} => C:\Program Files (x86)\Dropbox\Client\DropboxExt64.17.0.dll [2017-07-12] (Dropbox, Inc.)
ContextMenuHandlers06: [ESET Smart Security - Context Menu Shell Extension] -> {B089FE88-FB52-11D3-BDF1-0050DA34150D} => C:\Program Files\ESET\ESET Security\shellExt.dll [2017-07-11] (ESET)
ContextMenuHandlers06: [Kaspersky Anti-Virus 17.0.0] -> {39C9FA89-7012-4573-A92D-BFD1F8CA542D} => C:\Program Files (x86)\Kaspersky Lab\Kaspersky Total Security 17.0.0\x64\shellex.dll [2017-04-28] (AO Kaspersky Lab)
ContextMenuHandlers06: [RecuvaShellExt] -> {435E5DF5-2510-463C-B223-BDA47006D002} => C:\Program Files\Recuva\RecuvaShell64.dll [2016-06-06] (Piriform Ltd)
ContextMenuHandlers06: [WDSyncContextMenuHandler] -> {5A51BDCB-F8C2-4698-B79C-A77DF0AA466B} => C:\WINDOWS\system32\mscoree.dll [2017-03-18] (Microsoft Corporation)
 
==================== Scheduled Tasks (Whitelisted) =============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
Task: {005B78DE-9ECF-4C1D-85D3-6330FE864BA6} - System32\Tasks\GoogleUpdateTaskMachineCore1d040ece2e11a19 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {073958F3-8E5F-4CF7-8625-ABD15377481E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe [2017-06-22] (HP Inc.)
Task: {0A1E4A40-752E-425E-B7D0-0A0AE002C93C} - \Microsoft\Windows\Setup\gwx\launchtrayprocess -> No File <==== ATTENTION
Task: {259AE203-7AAC-4A0D-93DD-5EB4EE090A28} - \Microsoft\Windows\Setup\GWXTriggers\refreshgwxconfig-B -> No File <==== ATTENTION
Task: {264F49CB-3415-488D-B8DA-9F6F8BE48331} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - Resources => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {2E84AC4F-16D2-4F2F-AF13-EF11260452E1} - \Microsoft\Windows\Setup\GWXTriggers\Logon-5d -> No File <==== ATTENTION
Task: {2EE58945-C40B-43A8-A167-173E412D9D98} - System32\Tasks\GoogleUpdateTaskMachineCore1d0bf681e553bf8 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\WINDOWS\System32\AutoWorkplace.exe
Task: {3595EBB4-1238-4EA2-933E-200658FBF56C} - System32\Tasks\CLVDLauncher => c:\Program Files (x86)\CyberLink\Power2Go8\CLVDLauncher.exe [2013-03-12] (CyberLink Corp.)
Task: {37C32B19-9630-4A28-9E5A-8EA8CD06CFA2} - System32\Tasks\DropboxUpdateTaskMachineCore => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-24] (Dropbox, Inc.)
Task: {438F072B-AAE9-40AF-AC57-02A64C04DE3D} - \Microsoft\Windows\Setup\GWXTriggers\Time-5d -> No File <==== ATTENTION
Task: {46064571-564C-4D46-9842-A167DDF1D942} - System32\Tasks\GoogleUpdateTaskMachineCore1d08f601e825b6 => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {4AE24562-AD31-4B90-9AE5-ED4C785E4F09} - System32\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001 => C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\5530\g2mupdate.exe [2016-09-03] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {4F1C7B6F-3451-443B-A7EA-F05EF590C939} - \Microsoft\Windows\Setup\GWXTriggers\OutOfSleep-5d -> No File <==== ATTENTION
Task: {4FD0925E-6E79-4BC0-A382-3D5CCA5C36B1} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Product Configurator => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe [2017-06-28] (HP Inc.)
Task: {56FA405C-914E-41DB-A1DA-640837A26134} - System32\Tasks\Hewlett-Packard\HP Support Assistant\WarrantyChecker => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe [2017-04-06] (HP Inc.)
Task: {5DB34D0B-4B82-47F6-B06D-2D195446A83A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {64D6E437-C9F2-41B1-A5D6-C43A27ADAB7F} - System32\Tasks\HPCeeScheduleForAIRWORX 2 => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe [2015-06-16] (Hewlett-Packard)
Task: {70DBC4DD-6DE6-48DB-A77B-732338AD113D} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-12-19] (Adobe Systems Incorporated)
Task: {78F037B8-98B7-4FB4-8208-86D30D156F8F} - \Microsoft\Windows\Setup\gwx\refreshgwxconfig -> No File <==== ATTENTION
Task: {7A8C073B-9921-4385-A061-FF8B5410A453} - System32\Tasks\{39393239-4118-43A9-9EF4-579F68CFC882} => C:\WINDOWS\system32\pcalua.exe -a C:\PROGRA~2\SAAZOD\Uninstall\uninstall.exe -c "/U:C:\PROGRA~2\SAAZOD\Uninstall\uninstall.xml"
Task: {8258540A-E194-4B1C-A446-B100E53A7B7B} - System32\Tasks\Adobe Uninstaller => C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
Task: {8A6CE6D2-BAFF-47BD-B636-5632FA76D78E} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {8EE60D19-E484-4EC5-87B6-BEB1AE19CF50} - System32\Tasks\GoogleUpdateTaskMachineUA1cf8dc0ce6bb10d => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-08-27] (Google Inc.)
Task: {8F630B83-069D-434E-B4C4-59AD3C10A507} - System32\Tasks\[email protected] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe
Task: {916845C6-0741-433C-AC62-C4B3A5F302DB} - System32\Tasks\S-1-5-21-2671885098-678752524-1400920573-1001\DataSenseLiveTileTask => C:\WINDOWS\System32\DataUsageLiveTileTask.exe [2017-03-18] (Microsoft Corporation)
Task: {A06C2463-6FDA-437F-BFAC-91F03898B57C} - \OfficeSoftwareProtectionPlatform\SvcRestartTask -> No File <==== ATTENTION
Task: {A7CF62C0-17A6-42AB-A10F-9A6C446B7B33} - System32\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001 => C:\Users\AIRWORX 2\AppData\Local\Citrix\GoToMeeting\5530\g2mupload.exe [2016-09-03] (Citrix Online, a division of Citrix Systems, Inc.)
Task: {ACE8B2E6-FDA5-4314-A2D5-4B96CC439AEB} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2017-04-07] (HP Inc.)
Task: {AF0278DE-91EC-48AE-BDAF-F7FE516AF428} - System32\Tasks\{32B26120-173E-4516-BA92-CE080FB3608E} => C:\WINDOWS\system32\pcalua.exe -a F:\Display_menu.exe -d F:\
Task: {B9FA1D84-F00D-445B-8400-F7C7E90DD53E} - System32\Tasks\RGP Backup => C:\Program Files (x86)\Rock Gym Pro\Backup.exe [2017-06-04] ()
Task: {BB6E2A61-B56E-4672-A28A-0F8C30187EBA} - System32\Tasks\CLMLSvc_P2G8 => c:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2013-03-12] (CyberLink)
Task: {CE775C70-F807-4E1F-891C-712F82A9408E} - \Microsoft\Windows\Setup\GWXTriggers\MachineUnlock-5d -> No File <==== ATTENTION
Task: {D7E60E76-AB93-449D-99DB-17494EB2C958} - \Microsoft\Windows\Setup\GWXTriggers\OutOfIdle-5d -> No File <==== ATTENTION
Task: {E622463C-A190-4A30-A528-A6EF1AACE5FC} - System32\Tasks\DropboxUpdateTaskMachineUA => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe [2016-08-24] (Dropbox, Inc.)
Task: {E6505B7C-6B08-451F-A300-AF1087B421C6} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater => C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe [2016-12-07] (HP Inc.)
Task: {FF21E8DE-8636-41FE-897F-E34AEA4C31B9} - System32\Tasks\Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe [2016-11-07] (HP Inc.)
 
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
 
Task: C:\WINDOWS\Tasks\CreateExplorerShellUnelevatedTask.job => C:\WINDOWS\explorer.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineCore.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\DropboxUpdateTaskMachineUA.job => C:\Program Files (x86)\Dropbox\Update\DropboxUpdate.exe
Task: C:\WINDOWS\Tasks\G2MUpdateTask-S-1-5-21-2671885098-678752524-1400920573-1001.job => C:\Users\AIRWORX 2\AppData\Local\GoToMeeting\7297\g2mupdate.exe
Task: C:\WINDOWS\Tasks\G2MUploadTask-S-1-5-21-2671885098-678752524-1400920573-1001.job => C:\Users\AIRWORX 2\AppData\Local\GoToMeeting\7297\g2mupload.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d040ece2e11a19.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore1d08f601e825b6.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\WINDOWS\Tasks\HPCeeScheduleForAIRWORX 2.job => C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe
 
==================== Shortcuts & WMI ========================
 
(The entries could be listed to be restored or removed.)
 
 
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\9501e18d7c2ab92e\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 2"
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\69639df789022856\Google Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 1"
ShortcutWithArgument: C:\Users\AIRWORX 2\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\ImplicitAppShortcuts\48499db33039e897\Brandi - Chrome.lnk -> C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) -> --profile-directory="Profile 4"
 
==================== Loaded Modules (Whitelisted) ==============
 
2014-05-15 13:29 - 2005-04-21 21:36 - 00143360 ____R () C:\WINDOWS\system32\BrSNMP64.dll
2015-11-04 16:43 - 2015-11-04 16:43 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2010-01-15 12:46 - 2010-01-15 12:46 - 05820416 _____ () C:\Program Files (x86)\MySQL\MySQL Server 5.0\bin\mysqld-nt.exe
2005-09-09 03:24 - 2005-09-09 03:24 - 00102400 _____ () C:\Program Files (x86)\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
2017-03-18 13:58 - 2017-03-18 13:58 - 00138000 _____ () C:\WINDOWS\SYSTEM32\inputhost.dll
2017-06-23 03:56 - 2017-06-23 03:56 - 13207232 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41225.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Core.dll
2017-06-23 03:56 - 2017-06-23 03:56 - 01199816 _____ () C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.8241.41225.0_x64__8wekyb3d8bbwe\Office.UI.Xaml.Word.dll
2017-07-14 13:12 - 2017-07-14 13:12 - 04323840 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x64__8wekyb3d8bbwe\Calculator.exe
2017-07-14 04:41 - 2017-07-14 04:47 - 03500456 _____ () C:\Program Files\WindowsApps\Microsoft.WindowsCalculator_10.1706.1602.0_x64__8wekyb3d8bbwe\Microsoft.UI.Xaml.dll
2017-06-26 19:32 - 2017-06-22 20:21 - 02692440 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\swiftshader\libglesv2.dll
2017-06-26 19:32 - 2017-06-22 20:21 - 00137048 _____ () C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\swiftshader\libegl.dll
2017-03-18 13:59 - 2017-03-18 19:31 - 01731072 _____ () C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\Cortana.Core.dll
2014-12-11 17:40 - 2014-12-11 17:40 - 40622592 ____R () C:\Program Files (x86)\Fitbit Connect\libcef.dll
2015-04-03 17:08 - 2009-02-27 16:38 - 00139264 ____R () C:\Program Files (x86)\Brother\BrUtilities\BrLogAPI.dll
2017-07-13 13:47 - 2017-07-12 12:58 - 00746816 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_watchdog.dll
2017-07-13 13:47 - 2017-07-12 12:58 - 01787200 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_crashpad.dll
2015-12-11 01:07 - 2017-07-12 12:58 - 00100296 _____ () C:\Program Files (x86)\Dropbox\Client\_ctypes.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00018888 _____ () C:\Program Files (x86)\Dropbox\Client\select.pyd
2015-12-11 01:07 - 2017-07-12 13:01 - 00020800 _____ () C:\Program Files (x86)\Dropbox\Client\tornado.speedups.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00035792 _____ () C:\Program Files (x86)\Dropbox\Client\_multiprocessing.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._constant_time.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00125904 _____ () C:\Program Files (x86)\Dropbox\Client\_cffi_backend.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00694224 _____ () C:\Program Files (x86)\Dropbox\Client\unicodedata.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 01862992 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._openssl.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\cryptography.hazmat.bindings._padding.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00145864 _____ () C:\Program Files (x86)\Dropbox\Client\pyexpat.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00020432 _____ () C:\Program Files (x86)\Dropbox\Client\faulthandler.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00116688 _____ () C:\Program Files (x86)\Dropbox\Client\pywintypes27.dll
2015-12-11 01:07 - 2017-07-12 12:58 - 00105928 _____ () C:\Program Files (x86)\Dropbox\Client\win32api.pyd
2016-08-06 10:17 - 2017-07-12 13:01 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.crt.compiled._winffi_crt.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00062784 _____ () C:\Program Files (x86)\Dropbox\Client\psutil._psutil_windows.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00040248 _____ () C:\Program Files (x86)\Dropbox\Client\fastpath.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00024528 _____ () C:\Program Files (x86)\Dropbox\Client\win32event.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00392656 _____ () C:\Program Files (x86)\Dropbox\Client\pythoncom27.dll
2017-07-13 13:47 - 2017-07-12 12:58 - 00020936 _____ () C:\Program Files (x86)\Dropbox\Client\mmapfile.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00116176 _____ () C:\Program Files (x86)\Dropbox\Client\win32security.pyd
2015-12-11 01:07 - 2017-07-12 13:01 - 00392512 _____ () C:\Program Files (x86)\Dropbox\Client\win32com.shell.shell.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00124880 _____ () C:\Program Files (x86)\Dropbox\Client\win32file.pyd
2016-08-06 10:17 - 2017-07-12 13:01 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.kernel32.compiled._winffi_kernel32.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32clipboard.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00175560 _____ () C:\Program Files (x86)\Dropbox\Client\win32gui.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00030160 _____ () C:\Program Files (x86)\Dropbox\Client\win32pipe.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00043472 _____ () C:\Program Files (x86)\Dropbox\Client\win32process.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00048592 _____ () C:\Program Files (x86)\Dropbox\Client\win32service.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00057808 _____ () C:\Program Files (x86)\Dropbox\Client\win32evtlog.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00024016 _____ () C:\Program Files (x86)\Dropbox\Client\win32profile.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00022336 _____ () C:\Program Files (x86)\Dropbox\Client\cpuid.compiled._cpuid.pyd
2017-05-17 12:53 - 2017-07-12 13:01 - 00082264 _____ () C:\Program Files (x86)\Dropbox\Client\winenumhandles.compiled._WinEnumHandles.pyd
2015-12-11 01:07 - 2017-07-12 13:01 - 00025432 _____ () C:\Program Files (x86)\Dropbox\Client\winscreenshot.compiled._CaptureScreenshot.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00027488 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox.infinite.win.compiled._driverinstallation.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 03928896 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWidgets.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00083912 _____ () C:\Program Files (x86)\Dropbox\Client\sip.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 01826104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtCore.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 01972024 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtGui.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00028616 _____ () C:\Program Files (x86)\Dropbox\Client\win32ts.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00171336 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebEngineWidgets.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00042816 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebChannel.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00531264 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtNetwork.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00133432 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKit.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00224064 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWebKitWidgets.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00207680 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtPrintSupport.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00060880 _____ () C:\Program Files (x86)\Dropbox\Client\win32print.pyd
2017-02-24 11:41 - 2017-07-12 13:01 - 00054608 _____ () C:\Program Files (x86)\Dropbox\Client\winrpcserver.compiled._RPCServer.pyd
2017-01-23 12:26 - 2017-07-12 13:01 - 00022864 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.user32.compiled._winffi_user32.pyd
2016-04-15 15:18 - 2017-07-12 13:01 - 00069968 _____ () C:\Program Files (x86)\Dropbox\Client\windisplaytoast.compiled._DisplayToast.pyd
2017-01-23 12:26 - 2017-07-12 13:01 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.iphlpapi.compiled._winffi_iphlpapi.pyd
2017-01-23 12:26 - 2017-07-12 13:01 - 00021848 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winerror.compiled._winffi_winerror.pyd
2017-01-23 12:26 - 2017-07-12 13:01 - 00022872 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.wininet.compiled._winffi_wininet.pyd
2015-12-11 01:07 - 2017-07-12 12:58 - 00349128 _____ () C:\Program Files (x86)\Dropbox\Client\winxpgui.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00103232 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtWinExtras.pyd
2016-02-25 12:07 - 2017-07-12 13:01 - 00023896 _____ () C:\Program Files (x86)\Dropbox\Client\winverifysignature.compiled._VerifySignature.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00025936 _____ () C:\Program Files (x86)\Dropbox\Client\librsyncffi.compiled._librsyncffi.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00036296 _____ () C:\Program Files (x86)\Dropbox\Client\librsync.dll
2017-07-13 13:47 - 2017-07-12 12:59 - 00033112 _____ () C:\Program Files (x86)\Dropbox\Client\enterprise_data.compiled._enterprise_data.pyd
2017-07-13 13:47 - 2017-07-12 12:58 - 00293392 _____ () C:\Program Files (x86)\Dropbox\Client\EnterpriseDataAdapter.dll
2017-07-13 13:47 - 2017-07-12 12:59 - 00181056 _____ () C:\Program Files (x86)\Dropbox\Client\dropbox_sqlite_ext.DLL
2016-07-28 16:09 - 2017-07-12 13:01 - 00030536 _____ () C:\Program Files (x86)\Dropbox\Client\wind3d11.compiled._wind3d11.pyd
2017-07-13 13:47 - 2017-07-12 12:59 - 00024368 _____ () C:\Program Files (x86)\Dropbox\Client\libEGL.dll
2017-07-13 13:47 - 2017-07-12 12:59 - 01637688 _____ () C:\Program Files (x86)\Dropbox\Client\libGLESv2.dll
2016-08-06 10:17 - 2017-07-12 13:01 - 00026456 _____ () C:\Program Files (x86)\Dropbox\Client\winffi.winhttp.compiled._winffi_winhttp.pyd
2017-04-07 11:59 - 2017-07-12 13:01 - 00023368 _____ () C:\Program Files (x86)\Dropbox\Client\wincrashpad.compiled._Crashpad.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00546104 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQuick.pyd
2017-07-13 13:47 - 2017-07-12 13:00 - 00357688 _____ () C:\Program Files (x86)\Dropbox\Client\PyQt5.QtQml.pyd
2015-10-19 12:08 - 2017-07-12 12:58 - 00697304 _____ () C:\Program Files (x86)\Dropbox\Client\QtQuick\Controls\qtquickcontrolsplugin.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf
2013-03-26 12:18 - 2013-03-26 12:18 - 00414536 _____ () C:\Program Files (x86)\Nuance\PDFCreate\PDFCOffice2007Addin.dll
 
==================== Alternate Data Streams (Whitelisted) =========
 
(If an entry is included in the fixlist, only the ADS will be removed.)
 
 
==================== Safe Mode (Whitelisted) ===================
 
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
 
 
==================== Association (Whitelisted) ===============
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
 
 
==================== Internet Explorer trusted/restricted ===============
 
(If an entry is included in the fixlist, it will be removed from the registry.)
 
 
==================== Hosts content: ===============================
 
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
 
2013-08-22 06:25 - 2013-08-22 06:25 - 00000824 _____ C:\WINDOWS\system32\Drivers\etc\hosts
 
 
==================== Other Areas ============================
 
(Currently there is no automatic fix for this section.)
 
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\AIRWORX 2\AppData\Local\Microsoft\Windows\Themes\TranscodedWallpaper
HKU\S-1-5-21-2671885098-678752524-1400920573-500\Control Panel\Desktop\\Wallpaper -> 
DNS Servers: 68.105.28.11 - 68.105.29.11
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer => (SmartScreenEnabled: RequireAdmin)
Windows Firewall is disabled.
 
==================== MSCONFIG/TASK MANAGER disabled items ==
 
MSCONFIG\Services: CDPUserSvc_492c3 => 2
MSCONFIG\Services: CDPUserSvc_5d4d8 => 2
MSCONFIG\Services: GoToAssist => 3
MSCONFIG\Services: MessagingService_492c3 => 3
MSCONFIG\Services: MessagingService_5d4d8 => 3
MSCONFIG\Services: OneSyncSvc_492c3 => 2
MSCONFIG\Services: OneSyncSvc_5d4d8 => 2
HKLM\...\StartupApproved\StartupFolder: => "BackupRemind.lnk"
HKLM\...\StartupApproved\StartupFolder: => "Cox Cloud Drive.lnk"
HKLM\...\StartupApproved\Run: => "SysTrayApp"
HKLM\...\StartupApproved\Run: => "BeatsOSDApp"
HKLM\...\StartupApproved\Run: => "Lathem.USBTM.UI"
HKLM\...\StartupApproved\Run: => "Seagate Scheduler2 Service"
HKLM\...\StartupApproved\Run32: => "StartCCC"
HKLM\...\StartupApproved\Run32: => "Adobe ARM"
HKLM\...\StartupApproved\Run32: => "ISUSPM"
HKLM\...\StartupApproved\Run32: => "PPort14reminder"
HKLM\...\StartupApproved\Run32: => "IndexSearch"
HKLM\...\StartupApproved\Run32: => "PaperPort PTD"
HKLM\...\StartupApproved\Run32: => "PDFCreHook"
HKLM\...\StartupApproved\Run32: => "PDFProHook"
HKLM\...\StartupApproved\Run32: => "PDF7 Registry Controller"
HKLM\...\StartupApproved\Run32: => "EEventManager"
HKLM\...\StartupApproved\Run32: => "Adobe Photo Downloader"
HKLM\...\StartupApproved\Run32: => "iTunesHelper"
HKLM\...\StartupApproved\Run32: => "DiscWizardMonitor.exe"
HKLM\...\StartupApproved\Run32: => "Adobe Creative Cloud"
HKLM\...\StartupApproved\Run32: => "Vault Explorer Cache Watcher"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\StartupFolder: => "OneNote 2010 Screen Clipper and Launcher.lnk"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\StartupFolder: => "Verizon Wireless Software Utility Application for Android – Samsung.lnk"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\Run: => "OneDrive"
HKU\S-1-5-21-2671885098-678752524-1400920573-1001\...\StartupApproved\Run: => "SmartSwitchPDLR.exe"
 
==================== FirewallRules (Whitelisted) ===============
 
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
 
FirewallRules: [{00AA2407-5CF7-47A5-9DDD-F424A5691F7F}] => (Allow) C:\Program Files (x86)\Dropbox\Client\Dropbox.exe
FirewallRules: [{97357220-4D2F-4FFD-8DC2-EE30F08F979A}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{76B00221-8ED9-44B4-A9A8-180AA9701989}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{57CE1D01-0DD4-4864-9D49-CCD8D0024DB5}] => (Allow) %systemroot%\system32\alg.exe
FirewallRules: [{2042F16E-3442-4D60-B82C-3EBE56757C77}] => (Allow) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
FirewallRules: [UDP Query User{13D4495E-1B20-4E5F-BB5C-A466C9AF6EB6}C:\program files (x86)\escaperoom software\escaperoom.exe] => (Allow) C:\program files (x86)\escaperoom software\escaperoom.exe
FirewallRules: [TCP Query User{A1B22892-C13F-42B1-8B86-AEBC5293F339}C:\program files (x86)\escaperoom software\escaperoom.exe] => (Allow) C:\program files (x86)\escaperoom software\escaperoom.exe
FirewallRules: [{F86D4BC7-A6B7-4C8C-A170-9513779233C6}] => (Allow) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPDeviceDetection3.exe
FirewallRules: [{6C601AEC-C783-4F4C-9EE1-47CAA6B853EF}] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{50984AD4-0142-46A0-A1BA-A911B0EC88FD}] => (Block) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [UDP Query User{8E8846C5-505D-4C71-8E8C-191B20CE8CC1}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [TCP Query User{52A14CC1-81FA-4EE6-B8DE-2CACF81CFFC6}C:\program files (x86)\internet explorer\iexplore.exe] => (Allow) C:\program files (x86)\internet explorer\iexplore.exe
FirewallRules: [{C3205BCA-4BA3-41FC-AA89-9CB74ED73D31}] => (Allow) LPort=3306
FirewallRules: [{6E8725CD-1AF4-456C-95BE-7433E0345F7E}] => (Allow) LPort=9158
FirewallRules: [{543FD946-F6B3-40D9-9BBF-ACCF81C0236F}] => (Allow) LPort=9158
FirewallRules: [{2956BC6B-6623-4958-A14F-5E00BC677ABF}] => (Allow) LPort=9157
FirewallRules: [{8A44508B-F996-4654-837E-DAB5F21218A1}] => (Allow) LPort=9157
FirewallRules: [{5437C8FE-5F22-46EC-B6B2-0B5AB952D957}] => (Allow) LPort=9156
FirewallRules: [{C2CED3BA-1EF3-4A52-B85B-6A2C09B4735A}] => (Allow) LPort=9156
FirewallRules: [{9CE3BD30-DCEF-46F5-A6ED-18A72FDBA743}] => (Allow) F:\PayClock.msi
FirewallRules: [{D2A228E4-87A0-41F2-8492-E05EDA4722EF}] => (Allow) F:\PayClock.msi
FirewallRules: [{0CCAB027-1E9B-46F0-87B7-5F4E8B60C6FC}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{C88BD0D7-5FE7-444C-AD90-A5D04A20DE32}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{F6DCAE84-2BCF-4B40-9981-5766F41C4BAA}] => (Allow) LPort=9158
FirewallRules: [{29DAB202-4C52-4BA9-BD9B-FBB66BFE4FAF}] => (Allow) LPort=9158
FirewallRules: [{9DE5CCA7-5467-497F-8EB6-CFF0F22D8764}] => (Allow) LPort=9157
FirewallRules: [{A3C86F44-8286-42C0-A02E-B6338B0F2D39}] => (Allow) LPort=9157
FirewallRules: [{1C209DE4-FE08-436D-94BA-E53EE4D90DC0}] => (Allow) LPort=9156
FirewallRules: [{E94B8338-1446-4CB1-A308-71B8E309A6D4}] => (Allow) LPort=9156
FirewallRules: [{3FB4674A-0747-4F9B-AB77-6BA7352B143C}] => (Allow) F:\PayClock.msi
FirewallRules: [{461F524A-493F-40ED-95E3-8EE4AB1CB731}] => (Allow) F:\PayClock.msi
FirewallRules: [{6A610D4B-D3E3-4498-AFD1-0FCB8D9A127F}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{F85989A3-85BC-4C4B-82F9-1C84A5776FDE}] => (Allow) F:\PayClockInstaller.exe
FirewallRules: [{6607E655-6A17-4AEB-9CF3-D2F10926B44A}] => (Allow) C:\Users\AIRWORX 2\AppData\Local\Microsoft\OneDrive\OneDrive.exe
FirewallRules: [{A318E63F-3B16-4801-9A52-8B4EF2D8CBF2}] => (Allow) LPort=54925
FirewallRules: [{59577291-5221-4BDA-BA72-221D3ABCEF98}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{D28E8D57-6792-4E93-B3C2-F4A80976A2B9}] => (Allow) C:\Program Files (x86)\Brother\Brmfl10f\FAXRX.exe
FirewallRules: [{E4860DBD-DEE5-4EA8-A8C1-AD6BD8BEAD6E}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{82544E8E-2A02-40DA-8F04-ED87E9486D8B}] => (Allow) C:\Program Files (x86)\HPConnectedMusic\HPConnectedMusic.exe
FirewallRules: [{6A3DD6EE-BED5-4AD1-914E-140E9866E1F6}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{83B9CC3B-B79F-4C88-8D43-C8F3688F8D6C}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\HPConnectedMusic.exe
FirewallRules: [{3C4B403A-085B-4A2C-8D80-C00DBEC9724B}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{8665DBEC-6D37-4A9B-9101-D2CAC7461032}] => (Allow) %LocalAppData%\HPConnectedMusic\Application\spotify_helper.exe
FirewallRules: [{E54DD560-4B3D-4D46-BCCE-AA81477764BF}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{1E1FA9F8-B6FA-4E19-BCC7-036EC3CF76E7}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{B542B111-518D-4929-A9BE-87750DC19803}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{37B1CC24-7FE3-4E38-A0BB-779278DD3824}] => (Allow) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
FirewallRules: [{631897A6-FD9C-4FDB-A1EF-BE752E9D1AEF}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDirector10\PDR10.EXE
FirewallRules: [{A8F82A93-7DDC-4A37-B9F0-2246585ABAE8}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12.exe
FirewallRules: [{AB24DE43-BA75-4A2C-BE62-50EC8A6E71CA}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMR\PowerDVD12DMREngine.exe
FirewallRules: [{04B1FBED-801F-4783-AC19-44912DC3B82A}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Kernel\DMS\CLMSServerPDVD12.exe
FirewallRules: [{3F3018C7-7AB1-4BB7-8451-CF1337B3E27F}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12Agent.exe
FirewallRules: [{9B100BC8-9E14-4408-884D-571C33BF4424}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\PowerDVD12ML.exe
FirewallRules: [{35652560-AE8B-4178-B991-B3BAC7F69C8A}] => (Allow) c:\Program Files (x86)\CyberLink\PowerDVD12\Movie\PowerDVD.exe
FirewallRules: [{4C55D636-1062-42F2-83E0-88F52AC05F10}] => (Allow) C:\Users\Administrator\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{929B0F01-026B-4E9C-9C9F-034A6A3DF20E}] => (Allow) LPort=3306
FirewallRules: [{0FE1E20F-FA13-4A99-9282-E018DFB376A7}] => (Allow) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{2BB9BD43-1798-4BA0-ADC5-65DED0EA0609}] => (Allow) LPort=2869
FirewallRules: [{20796F92-7CAA-439B-BDBC-424E5856A4B8}] => (Allow) LPort=1900
FirewallRules: [{7683262D-2F71-4302-A78C-09531E02C619}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{0AF54D7F-6D16-45D1-B795-D5E09C279A94}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeCam.exe
FirewallRules: [{B5519C34-E5E2-4002-BC5C-43764B8FE077}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{D0AF0B79-A58E-4981-AE18-493996ED77D1}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeEnC2.exe
FirewallRules: [{506FBEB2-08E3-4748-AA99-035C39352EC2}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{94B15C71-D0F4-4920-92AA-CFB64A40F500}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe
FirewallRules: [{68E02351-34A3-4E1C-B584-1408332366E9}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{40460E99-D235-4736-A77C-629162D4C564}] => (Allow) C:\Program Files (x86)\Microsoft LifeCam\LifeTray.exe
FirewallRules: [{DF41382D-7C4B-452D-95F1-8086F0DAC591}] => (Allow) C:\Program Files (x86)\Skype\Phone\Skype.exe
FirewallRules: [{DC1F597B-7AF8-4E42-800A-A1D016805D6B}] => (Allow) C:\Users\AIRWORX 2\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{240C5F7D-30D8-4682-ACE9-2D695BBBA114}] => (Allow) %systemroot%\system32\alg.exe
 
==================== Restore Points =========================
 
14-07-2017 09:02:15 Windows Update
 
==================== Faulty Device Manager Devices =============
 
 
==================== Event log errors: =========================
 
Application errors:
==================
Error: (07/17/2017 12:12:31 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AccountsControlHost.exe, version: 10.0.15063.0, time stamp: 0x58ccbdcb
Faulting module name: Windows.UI.Xaml.dll, version: 10.0.15063.483, time stamp: 0xb0271b92
Exception code: 0xc0000409
Fault offset: 0x00000000000b0430
Faulting process id: 0x2b00
Faulting application start time: 0x01d2ff30a3af16f6
Faulting application path: C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy\AccountsControlHost.exe
Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll
Report Id: 30205cf5-aed3-44f5-b075-c49b1280c3f3
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/17/2017 12:05:30 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: AccountsControlHost.exe, version: 10.0.15063.0, time stamp: 0x58ccbdcb
Faulting module name: Windows.UI.Xaml.dll, version: 10.0.15063.483, time stamp: 0xb0271b92
Exception code: 0xc0000409
Fault offset: 0x00000000000b0430
Faulting process id: 0x34ec
Faulting application start time: 0x01d2ff2fa79755a7
Faulting application path: C:\Windows\SystemApps\Microsoft.AccountsControl_cw5n1h2txyewy\AccountsControlHost.exe
Faulting module path: C:\Windows\System32\Windows.UI.Xaml.dll
Report Id: d4fc27cf-b066-4d9d-b5a2-d8bab9687314
Faulting package full name: 
Faulting package-relative application ID:
 
Error: (07/17/2017 07:41:27 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "WmiApRpl" in DLL "C:\WINDOWS\system32\wbem\wmiaprpl.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (07/17/2017 07:41:27 AM) (Source: PerfNet) (EventID: 2004) (User: )
Description: Unable to open the Server service performance object. The first four bytes (DWORD) of the Data section contains the status code.
 
Error: (07/17/2017 07:41:26 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "Lsa" in DLL "C:\Windows\System32\Secur32.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (07/17/2017 07:41:26 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "ESENT" in DLL "C:\WINDOWS\system32\esentprf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (07/17/2017 07:41:26 AM) (Source: Perflib) (EventID: 1008) (User: )
Description: The Open Procedure for service "BITS" in DLL "C:\Windows\System32\bitsperf.dll" failed. Performance data for this service will not be available. The first four bytes (DWORD) of the Data section contains the error code.
 
Error: (07/17/2017 07:11:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program mmc.exe version 10.0.15063.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Security and Maintenance control panel.
 
Process ID: 25c4
 
Start Time: 01d2ff066f803283
 
Termination Time: 19
 
Application Path: C:\Windows\System32\mmc.exe
 
Report Id: 11129034-2c09-49ee-bfb5-357d4fbf7887
 
Faulting package full name: 
 
Faulting package-relative application ID:
 
Error: (07/17/2017 04:06:28 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nuance\PaperPort\CheckPPFolders.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
 
Error: (07/16/2017 04:06:37 AM) (Source: SideBySide) (EventID: 78) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Nuance\PaperPort\CheckPPFolders.exe".Error in manifest or policy file "" on line .
A component version required by the application conflicts with another component version already active.
Conflicting components are:.
Component 1: C:\WINDOWS\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_6dad63fefc436da8.manifest.
Component 2: C:\WINDOWS\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.15063.483_none_26002d27e7c744a2.manifest.
 
 
System errors:
=============
Error: (07/17/2017 07:43:42 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error: 
This driver has been blocked from loading
 
Error: (07/17/2017 07:43:42 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\AIRWOR~2\AppData\Local\Temp\ehdrv.sys
 
Error: (07/17/2017 07:43:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error: 
This driver has been blocked from loading
 
Error: (07/17/2017 07:43:41 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\AIRWOR~2\AppData\Local\Temp\ehdrv.sys
 
Error: (07/17/2017 07:43:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error: 
This driver has been blocked from loading
 
Error: (07/17/2017 07:43:41 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\AIRWOR~2\AppData\Local\Temp\ehdrv.sys
 
Error: (07/17/2017 07:43:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error: 
This driver has been blocked from loading
 
Error: (07/17/2017 07:43:41 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\AIRWOR~2\AppData\Local\Temp\ehdrv.sys
 
Error: (07/17/2017 07:43:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: The eapihdrv service failed to start due to the following error: 
This driver has been blocked from loading
 
Error: (07/17/2017 07:43:41 AM) (Source: Application Popup) (EventID: 1060) (User: )
Description: \??\C:\Users\AIRWOR~2\AppData\Local\Temp\ehdrv.sys
 
 
CodeIntegrity:
===================================
  Date: 2017-07-14 10:34:32.469
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:34:32.464
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:24:31.727
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:24:31.725
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:03:31.173
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:03:31.166
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:02:35.857
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:02:35.855
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:02:33.295
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
  Date: 2017-07-14 10:02:33.293
  Description: Code Integrity determined that a process (\Device\HarddiskVolume4\Program Files\ESET\ESET Security\ekrn.exe) attempted to load \Device\HarddiskVolume4\Program Files\Bonjour\mdnsNSP.dll that did not meet the Custom 3 / Antimalware signing level requirements.
 
 
==================== Memory info =========================== 
 
Processor: AMD A8-6500 APU with Radeon™ HD Graphics 
Percentage of memory in use: 63%
Total physical RAM: 7365.48 MB
Available physical RAM: 2684 MB
Total Virtual: 7765.48 MB
Available Virtual: 2404.89 MB
 
==================== Drives ================================
 
Drive c: (Windows) (Fixed) (Total:1842.47 GB) (Free:1668.89 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive d: (Recovery Image) (Fixed) (Total:18.63 GB) (Free:2.32 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive e: (New Volume) (Fixed) (Total:298.09 GB) (Free:172.78 GB) NTFS
Drive i: () (Removable) (Total:59.47 GB) (Free:59.47 GB) exFAT
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (Size: 1863 GB) (Disk ID: 8834CD72)
 
Partition: GPT.
 
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 298.1 GB) (Disk ID: 497B7DD2)
Partition 1: (Not Active) - (Size=298.1 GB) - (Type=07 NTFS)
 
========================================================
Disk: 3 (MBR Code: Windows 7 or 8) (Size: 59.5 GB) (Disk ID: 5D64B022)
Partition 1: (Active) - (Size=59.5 GB) - (Type=07 NTFS)
 
==================== End of Addition.txt ============================

  • 0

#42
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Then these are the logs I'd sent directly, re-posted in here. 

 

Informational 35993 5/30/2017 19:38 Microsoft-Windows-Kernel-General 1 Possible detection of CVE: 2017-05-31T02:38:59.368000000Z
Additional Information: 2017-05-31T02:38:59.370423200Z
 
This Event is generated when an attempt to exploit a known vulnerability (2017-05-31T02:38:59.368000000Z) is detected.
This Event is raised by a User mode process.       Informational 35992 5/30/2017 19:38 Microsoft-Windows-Kernel-General 1 Possible detection of CVE: 2017-05-31T02:38:59.367000000Z
Additional Information: 2017-05-31T02:38:59.368490500Z
 
This Event is generated when an attempt to exploit a known vulnerability (2017-05-31T02:38:59.367000000Z) is detected.
This Event is raised by a User mode process.       Informational 35991 5/30/2017 19:38 Microsoft-Windows-Time-Service 35 The time service is now synchronizing the system time with the time source time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->13.65.245.138:123).     Informational 35990 5/30/2017 19:38 Microsoft-Windows-Kernel-General 1 Possible detection of CVE: 2017-05-31T02:38:59.367470800Z
Additional Information: 2017-05-31T02:38:56.810850900Z
 
This Event is generated when an attempt to exploit a known vulnerability (2017-05-31T02:38:59.367470800Z) is detected.
This Event is raised by a User mode process.       Informational 35989 5/30/2017 19:38 Microsoft-Windows-Time-Service 37 The time provider NtpClient is currently receiving valid time data from time.windows.com,0x9 (ntp.m|0x9|0.0.0.0:123->13.65.245.138:123).     Informational 35988 5/30/2017 19:38 Microsoft-Windows-Time-Service 158 The time provider 'VMICTimeProvider' has indicated that the current hardware and operating environment is not supported and has stopped. This behavior is expected for VMICTimeProvider on non-HyperV-guest environments. This may be the expected behavior for the current provider in the current operating environment as well.
 
 
I've suspected it to be a problem with an update or vulnerability with chrome, so I'm also pasting the log for that...
 
[0515/202748.221:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z" --verbose-logging --do-not-launch-chrome
[0515/202748.221:VERBOSE1:setup_main.cc(1349)] system install is 1
[0515/202748.221:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0515/202748.221:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0515/202748.252:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0515/202748.346:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0515/202748.346:VERBOSE1:setup_main.cc(663)] Entered background processing mode.
[0515/202748.862:VERBOSE1:setup_main.cc(667)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0515/202749.377:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0515/202750.237:VERBOSE1:setup_main.cc(1099)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z
[0515/202750.752:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_4707C.tmp\CHROME.PACKED.7Z
[0515/202751.268:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/202922.825:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\chrome.7z
[0515/202923.372:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/203307.101:VERBOSE1:setup_main.cc(1158)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415
[0515/203307.867:VERBOSE1:setup_util.cc(291)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin
[0515/203308.023:VERBOSE1:setup_util.cc(302)] directory found: 58.0.3029.110
[0515/203308.023:VERBOSE1:setup_main.cc(1169)] version to install: 58.0.3029.110
[0515/203308.023:VERBOSE1:install.cc(324)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin
[0515/203308.039:VERBOSE1:install_worker.cc(273)] Adding unregistration items for DelegateExecute verb handler.
[0515/203308.039:VERBOSE1:install_worker.cc(785)] Adding unregistration items for per-user Metro keys.
[0515/203308.039:VERBOSE1:install_worker.cc(809)] Adding registration items for Active Setup.
[0515/203308.039:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0515/203308.039:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0515/203308.352:VERBOSE1:copy_tree_work_item.cc(62)] Copied source file C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\chrome.exe to alternative path C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_1232_24242\chrome.VisualElementsManifest.xml
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0515/203308.352:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\Chrome-bin\58.0.3029.110 to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer
[0515/203308.352:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0515/203308.571:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe
[0515/203308.617:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_4707C.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrmstp.exe
[0515/203308.617:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source1232_7415\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\chrome.7z
[0515/203309.133:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\CLSID\{5C65F4B0-3651-4514-B207-D10CB699B14B}
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Google\Chrome\Metro
[0515/203309.164:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Google\Chrome\Metro
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0515/203309.164:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0515/203309.899:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0515/203310.289:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0515/203310.618:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0515/203311.102:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list InUseUpdateWorkItemList
[0515/203311.102:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0515/203311.102:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list InUseUpdateWorkItemList
[0515/203311.102:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0515/203311.102:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list RegularUpdateWorkItemList
[0515/203311.102:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0515/203311.102:VERBOSE1:install.cc(234)] Version updated to 58.0.3029.110 while running 58.0.3029.96
[0515/203311.102:VERBOSE1:installer_state.cc(282)] ap: -full
[0515/203311.102:VERBOSE1:install.cc(111)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.414:VERBOSE1:install.cc(111)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.446:WARNING:install.cc(109)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.446:VERBOSE1:install.cc(111)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0515/203311.477:VERBOSE1:install.cc(131)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0515/203311.993:VERBOSE1:setup_util.cc(691)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0515/203312.149:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0515/203312.149:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0515/203312.462:VERBOSE1:install.cc(450)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0515/203312.462:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0515/203312.462:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0515/203312.477:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\ChromeExt
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\.crx
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\ChromeExt
[0515/203312.477:VERBOSE1:install_util.cc(310)] Deleting registry key Software\Classes\.crx
[0515/203312.477:VERBOSE1:product.cc(115)] LaunchUserExperiment status: 30 product: Google Chrome system_level: 1
[0515/203312.477:VERBOSE1:user_experiment.cc(437)] Toast experiment is disabled.
[0515/203312.477:VERBOSE1:setup_main.cc(1305)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0515/203312.477:VERBOSE1:google_update_settings.cc(474)] Removed incremental installer failure key; switching to channel:
[0515/203312.477:VERBOSE1:setup_main.cc(1507)] Installation complete, returning: 0
[0515/203312.774:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170515203312.pma
[0521/092347.578:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --rename-chrome-exe --system-level --verbose-logging
[0521/092347.592:VERBOSE1:setup_main.cc(1349)] system install is 1
[0521/092347.594:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.595:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0521/092347.628:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0521/092347.631:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.632:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0521/092347.634:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Application\chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\old_chrome.exe
[0521/092347.635:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0521/092347.635:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0521/092347.637:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0521/092347.637:VERBOSE1:install.cc(598)] Launching ""C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --delete-old-versions --system-level --verbose-logging" to delete old versions.
[0521/092347.648:VERBOSE1:setup_main.cc(472)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0521/092347.650:WARNING:self_cleaning_temp_dir.cc(84)] Failed to delete temporary directory C:\Program Files (x86)\Google\Chrome\Temp. Scheduling for deletion at reboot.
[0521/092347.661:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe" --delete-old-versions --system-level --verbose-logging
[0521/092347.661:VERBOSE1:setup_main.cc(1349)] system install is 1
[0521/092347.661:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8768_32057\old_chrome.exe
[0521/092347.662:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.662:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0521/092347.662:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_8768_32057
[0521/092347.662:VERBOSE1:delete_after_reboot_helper.cc(93)] Scheduled for deletion: C:\Program Files (x86)\Google\Chrome\Temp
[0521/092347.685:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0521/092347.686:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0521/092347.722:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170521092347.pma
[0521/092402.778:WARNING:delete_old_versions.cc(92)] Attempting to delete stray directory C:\Program Files (x86)\Google\Chrome\Application\58.0.3029.96
[0521/092403.419:VERBOSE1:setup_main.cc(387)] Successfully deleted all old files from --delete-old-versions process.
[0521/092403.482:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170521092403.pma
[0624/083032.355:VERBOSE1:setup_main.cc(1343)] Command Line: "C:\Program" --update-setup-exe="C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z" --new-setup-exe="C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe" --verbose-logging --do-not-launch-chrome Files "(x86)\Google\Chrome\Application\58.0.3029.110\Installer\setup.exe"
[0624/083032.385:VERBOSE1:setup_main.cc(1349)] system install is 1
[0624/083032.387:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083032.388:VERBOSE1:setup_main.cc(1357)] is_migrating_to_single is 0
[0624/083032.646:VERBOSE1:install_util.cc(223)] Windows NT 10.0.14393
[0624/083032.648:VERBOSE1:setup_main.cc(832)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z
[0624/083032.648:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\SETUP_PATCH.PACKED.7Z
[0624/083032.648:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\WINDOWS\TEMP\scoped_dir984_712
[0624/083035.111:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170624083034.pma
[0624/083036.315:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z" --previous-version=58.0.3029.110 --verbose-logging --do-not-launch-chrome
[0624/083036.355:VERBOSE1:setup_main.cc(1348)] system install is 1
[0624/083036.356:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083036.356:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0624/083036.491:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0624/083036.493:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0624/083036.494:VERBOSE1:setup_main.cc(662)] Entered background processing mode.
[0624/083036.494:VERBOSE1:setup_main.cc(666)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0624/083036.495:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0624/083036.505:VERBOSE1:setup_main.cc(1098)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z
[0624/083036.517:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_87F7D.tmp\CHROME_PATCH.PACKED.7Z
[0624/083036.517:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083401.776:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\chrome.7z
[0624/083401.777:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083610.542:VERBOSE1:setup_main.cc(1157)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165
[0624/083610.543:VERBOSE1:setup_util.cc(321)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin
[0624/083610.544:VERBOSE1:setup_util.cc(332)] directory found: 59.0.3071.109
[0624/083610.544:VERBOSE1:setup_main.cc(1168)] version to install: 59.0.3071.109
[0624/083610.622:VERBOSE1:install.cc(325)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin
[0624/083610.636:VERBOSE1:install_worker.cc(787)] Adding unregistration items for per-user Metro keys.
[0624/083610.636:VERBOSE1:install_worker.cc(813)] Adding registration items for Active Setup.
[0624/083610.637:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0624/083610.637:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0624/083610.637:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0624/083610.638:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0624/083610.701:VERBOSE1:copy_tree_work_item.cc(62)] Copied source file C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\chrome.exe to alternative path C:\Program Files (x86)\Google\Chrome\Application\new_chrome.exe
[0624/083610.711:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_6020_17361\chrome.VisualElementsManifest.xml
[0624/083610.712:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0624/083610.714:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\Chrome-bin\59.0.3071.109 to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109
[0624/083610.714:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer
[0624/083610.715:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer
[0624/083610.716:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0624/083610.772:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\setup.exe
[0624/083610.806:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_87F7D.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\chrmstp.exe
[0624/083610.808:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source6020_25165\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109\Installer\chrome.7z
[0624/083610.809:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0624/083610.810:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0624/083610.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0624/083611.100:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0624/083611.101:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0624/083611.251:ERROR:install_worker.cc(148)] Failed creating a firewall rules. Continuing with install.
[0624/083611.252:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0624/083611.252:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0624/083611.252:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0624/083611.253:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list InUseUpdateWorkItemList
[0624/083611.253:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0624/083611.253:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list InUseUpdateWorkItemList
[0624/083611.254:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0624/083611.254:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list RegularUpdateWorkItemList
[0624/083611.254:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0624/083611.255:VERBOSE1:install.cc(235)] Version updated to 59.0.3071.109 while running 58.0.3029.110
[0624/083611.256:VERBOSE1:installer_state.cc(283)] ap: -full
[0624/083611.256:VERBOSE1:install.cc(112)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.325:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.326:VERBOSE1:install.cc(112)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.327:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.328:VERBOSE1:install.cc(112)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0624/083611.527:VERBOSE1:install.cc(132)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0624/083611.527:VERBOSE1:setup_util.cc(721)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0624/083611.528:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0624/083611.530:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0624/083612.034:VERBOSE1:install.cc(451)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0624/083612.538:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0624/083613.055:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0624/083613.566:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0624/083614.089:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0624/083614.594:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0624/083615.098:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0624/083615.602:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0624/083616.107:VERBOSE1:product.cc(119)] LaunchUserExperiment status: 30 product: Google Chrome system_level: 1
[0624/083616.611:VERBOSE1:user_experiment.cc(437)] Toast experiment is disabled.
[0624/083617.115:VERBOSE1:setup_main.cc(1304)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0624/083617.629:VERBOSE1:google_update_settings.cc(475)] Removed incremental installer failure key; switching to channel:
[0624/083618.290:VERBOSE1:setup_main.cc(1506)] Installation complete, returning: 0
[0624/083619.170:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170624083619.pma
[0626/192841.405:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\Program" --update-setup-exe="C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z" --new-setup-exe="C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe" --verbose-logging --do-not-launch-chrome Files "(x86)\Google\Chrome\Application\59.0.3071.109\Installer\setup.exe"
[0626/192841.431:VERBOSE1:setup_main.cc(1348)] system install is 1
[0626/192841.434:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/192841.435:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0626/192939.613:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0626/192939.627:VERBOSE1:setup_main.cc(831)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z
[0626/192939.627:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\SETUP_PATCH.PACKED.7Z
[0626/192939.627:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\WINDOWS\TEMP\scoped_dir6980_30351
[0626/192940.371:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170626192939.pma
[0626/193038.499:VERBOSE1:setup_main.cc(1342)] Command Line: "C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe" --install-archive="C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z" --previous-version=59.0.3071.109 --verbose-logging --do-not-launch-chrome
[0626/193038.531:VERBOSE1:setup_main.cc(1348)] system install is 1
[0626/193038.533:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/193038.533:VERBOSE1:setup_main.cc(1356)] is_migrating_to_single is 0
[0626/193136.633:VERBOSE1:install_util.cc(217)] Windows NT 10.0.14393
[0626/193136.635:VERBOSE1:installer_state.cc(74)] Install distribution: Google Chrome
[0626/193136.636:VERBOSE1:setup_main.cc(662)] Entered background processing mode.
[0626/193136.636:VERBOSE1:setup_main.cc(666)] Installing to C:\Program Files (x86)\Google\Chrome\Application
[0626/193136.637:VERBOSE1:setup_main.cc(552)] Created path C:\Program Files (x86)\Google\Chrome\Temp
[0626/193136.638:VERBOSE1:setup_main.cc(1098)] Installing Chrome from compressed archive C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z
[0626/193136.662:VERBOSE1:lzma_util.cc(110)] Opening archive C:\WINDOWS\TEMP\CR_B4586.tmp\CHROME_PATCH.PACKED.7Z
[0626/193136.663:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193237.373:VERBOSE1:lzma_util.cc(110)] Opening archive C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\chrome.7z
[0626/193237.374:VERBOSE1:lzma_util.cc(116)] Uncompressing archive to path C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193250.735:VERBOSE1:setup_main.cc(1157)] unpacked to C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817
[0626/193250.735:VERBOSE1:setup_util.cc(321)] Looking for Chrome version folder under C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin
[0626/193250.736:VERBOSE1:setup_util.cc(332)] directory found: 59.0.3071.115
[0626/193250.736:VERBOSE1:setup_main.cc(1168)] version to install: 59.0.3071.115
[0626/193251.252:VERBOSE1:install.cc(325)] Successfully wrote chrome.VisualElementsManifest.xml to C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin
[0626/193251.419:VERBOSE1:install_worker.cc(787)] Adding unregistration items for per-user Metro keys.
[0626/193251.587:VERBOSE1:install_worker.cc(813)] Adding registration items for Active Setup.
[0626/193251.588:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list
[0626/193251.588:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Temp
[0626/193251.589:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application
[0626/193251.590:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics
[0626/193251.628:VERBOSE1:copy_tree_work_item.cc(85)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_3892_3436\chrome.exe
[0626/193252.752:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\chrome.exe to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0626/193252.754:VERBOSE1:move_tree_work_item.cc(80)] Moved destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml to backup path C:\Program Files (x86)\Google\Chrome\Temp\scoped_dir_3892_12452\chrome.VisualElementsManifest.xml
[0626/193252.755:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\chrome.VisualElementsManifest.xml to destination C:\Program Files (x86)\Google\Chrome\Application\chrome.VisualElementsManifest.xml
[0626/193252.756:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\Chrome-bin\59.0.3071.115 to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115
[0626/193252.757:VERBOSE1:create_dir_work_item.cc(33)] creating directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer
[0626/193252.757:VERBOSE1:create_dir_work_item.cc(38)] top directory that needs to be created: C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer
[0626/193252.758:VERBOSE1:create_dir_work_item.cc(40)] directory creation result: 1
[0626/193252.877:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\setup.exe
[0626/193253.721:VERBOSE1:copy_tree_work_item.cc(97)] Copied source C:\WINDOWS\TEMP\CR_B4586.tmp\setup.exe to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrmstp.exe
[0626/193253.724:VERBOSE1:move_tree_work_item.cc(92)] Moved source C:\Program Files (x86)\Google\Chrome\Temp\source3892_2817\chrome.7z to destination C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\chrome.7z
[0626/193253.727:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0626/193253.728:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Google\Chrome\Metro
[0626/193351.810:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: SendsPings does not exist.
[0626/193351.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: WebAccessible does not exist.
[0626/193351.811:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96}\Commands\on-os-upgrade or Value: RunAsUser does not exist.
[0626/193351.872:ERROR:install_worker.cc(148)] Failed creating a firewall rules. Continuing with install.
[0626/193351.873:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\ClientState\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: DowngradeVersion does not exist.
[0626/193351.873:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating InUseUpdateWorkItemList condition...
[0626/193351.873:VERBOSE1:conditional_work_item_list.cc(22)] No work to do in condition work item list InUseUpdateWorkItemList
[0626/193351.874:VERBOSE1:conditional_work_item_list.cc(17)] Evaluating RegularUpdateWorkItemList condition...
[0626/193351.874:VERBOSE1:conditional_work_item_list.cc(19)] Beginning conditional work item list
[0626/193351.874:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list RegularUpdateWorkItemList
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: opv does not exist.
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cpv does not exist.
[0626/193351.875:VERBOSE1:delete_reg_value_work_item.cc(47)] (delete value) Key: Software\Google\Update\Clients\{8A69D345-D564-463c-AFF1-A69D9E530F96} or Value: cmd does not exist.
[0626/193351.876:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list RegularUpdateWorkItemList
[0626/193351.876:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list
[0626/193351.876:VERBOSE1:install.cc(239)] Version updated to 59.0.3071.115
[0626/193351.878:VERBOSE1:installer_state.cc(283)] ap: -full
[0626/193351.879:VERBOSE1:install.cc(112)] Overwriting all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.881:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) all-users Desktop "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.882:VERBOSE1:install.cc(112)] Overwriting per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.883:WARNING:install.cc(110)] Failed: Overwriting (maybe the shortcut doesn't exist?) per-user Quick Launch "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193351.901:VERBOSE1:install.cc(112)] Overwriting all-users Start menu "Google Chrome" shortcut to C:\Program Files (x86)\Google\Chrome\Application\chrome.exe.
[0626/193352.030:VERBOSE1:install.cc(132)] Adding Chrome to Media player list at Software\Microsoft\MediaPlayer\ShimInclusionList\chrome.exe
[0626/193352.054:VERBOSE1:setup_util.cc(721)] Registering Chrome's event log provider at SYSTEM\CurrentControlSet\Services\EventLog\Application\Chrome
[0626/193352.054:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Register event log provider
[0626/193842.460:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Register event log provider
[0626/193842.461:VERBOSE1:install.cc(451)] Registering Chrome as browser: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
[0626/193842.461:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\Chrome\.exe\shell\run
[0626/193842.466:WARNING:delete_old_versions.cc(92)] Attempting to delete stray directory C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.109
[0626/193842.505:VERBOSE1:work_item_list.cc(34)] Beginning execution of work item list Write Installer Result
[0626/193842.506:VERBOSE1:work_item_list.cc(55)] Successful execution of work item list Write Installer Result
[0626/193842.506:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0626/193842.507:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0626/193842.508:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\ChromeExt
[0626/193842.508:VERBOSE1:install_util.cc(295)] Deleting registry key Software\Classes\.crx
[0626/193842.508:VERBOSE1:product.cc(119)] LaunchUserExperiment status: 2 product: Google Chrome system_level: 1
[0626/193842.522:VERBOSE1:user_experiment.cc(244)] LaunchSetupAsConsoleUser launching "C:\Program Files (x86)\Google\Chrome\Application\59.0.3071.115\Installer\setup.exe" --system-level-toast --system-level --verbose-logging --toast-results-key=740
[0626/193940.705:VERBOSE1:user_experiment.cc(247)] LaunchSetupAsConsoleUser   result: 1
[0626/193940.706:VERBOSE1:setup_main.cc(1304)] Deleting temporary directory C:\Program Files (x86)\Google\Chrome\Temp
[0626/193940.761:VERBOSE1:google_update_settings.cc(475)] Removed incremental installer failure key; switching to channel:
[0626/193940.773:VERBOSE1:setup_main.cc(1506)] Installation complete, returning: 0
[0626/193940.835:VERBOSE1:persistent_histogram_storage.cc(60)] Persistent histograms saved in file: C:\Program Files (x86)\Google\Chrome\Application\SetupMetrics\20170626193940.pma

  • 0

#43
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

Kaspersky did not find any malware so you can uninstall it.

 

Your odd usernames seems to be normal:

 

https://answers.micr...63-63ddb7ad7aa4

 

https://mspoweruser....rk-app-updated/

 

The onedrive stuff I know nothing about but judging by the date it's been there a while so not due to infection.  This is actually the SkyDrive program renamed so I assume you can uninstall it if you don't use it.  There is also something about credential manager:

 

Search for

 "Credential Manager".

b. Click on the arrow near the "OneDrive cached credentials".

c. Check whether the OneDrive login credentials are listed over there.

d. If the credentials are listed, I suggest you to click on "Remove from vault and follow the onscreen suggestions.

e. Login to the OneDrive again and check whether the credentials are getting saved.

 

The CVE values from ESET do not seem to be in the correct format so I can't look them up.  Are you still seeing the warnings?

 

 


  • 0

#44
BrandiCopas

BrandiCopas

    Member

  • Topic Starter
  • Member
  • PipPip
  • 79 posts

Good morning, so this time, I ran a complete scan, with Kaspersky, and it found a few items, they are as follows...

 

18.07.2017 23.46.42;Detected object (email attachment) not processed;C:\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\AIRWORX Email\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/03/16 10:34:32]//FedEx-Delivery-Details-ID-PNJ0FYKG.zip//FedEx-Delivery-Details-ID-PNJ0FYKG/FedEx-Delivery-Details-ID-PNJ0FYKG.doc.js;C:\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\AIRWORX Email\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/03/16 10:34:32]//FedEx-Delivery-Details-ID-PNJ0FYKG.zip//FedEx-Delivery-Details-ID-PNJ0FYKG/FedEx-Delivery-Details-ID-PNJ0FYKG.doc.js;HEUR:Trojan.Script.Agent.gen;Trojan program;07/18/2017 23:46:42
19.07.2017 02.50.30;Detected object (email attachment) not processed;\\AIRWORX2-PC\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\AIRWORX Email\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/03/16 10:34:32]//FedEx-Delivery-Details-ID-PNJ0FYKG.zip//FedEx-Delivery-Details-ID-PNJ0FYKG/FedEx-Delivery-Details-ID-PNJ0FYKG.doc.js;\\AIRWORX2-PC\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\AIRWORX Email\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/03/16 10:34:32]//FedEx-Delivery-Details-ID-PNJ0FYKG.zip//FedEx-Delivery-Details-ID-PNJ0FYKG/FedEx-Delivery-Details-ID-PNJ0FYKG.doc.js;HEUR:Trojan.Script.Agent.gen;Trojan program;07/19/2017 02:50:30
19.07.2017 02.41.36;Detected object (file) deleted;E:\Program Files\MGI\MGI PhotoSuite III SE\PS_Clean.exe;E:\Program Files\MGI\MGI PhotoSuite III SE\PS_Clean.exe;Trojan.Win32.Skillis.bhgl;Trojan program;07/19/2017 02:41:36
19.07.2017 02.41.30;Detected object (file) disinfected;E:\BRANDI-HP\Backup Set 2012-06-07 004433\Backup Files 2012-06-25 002811\Backup files 1.zip;E:\BRANDI-HP\Backup Set 2012-06-07 004433\Backup Files 2012-06-25 002811\Backup files 1.zip;;Unknown object;07/19/2017 02:41:30
19.07.2017 02.41.30;Detected object (file) deleted;E:\BRANDI-HP\Backup Set 2012-06-07 004433\Backup Files 2012-06-25 002811\Backup files 1.zip//C\Users\Brandi\AppData\Roaming\WildTangent\Updater\GameConsole\GameConsole-4.0.19.44-to-4.0.20.47.exe;E:\BRANDI-HP\Backup Set 2012-06-07 004433\Backup Files 2012-06-25 002811\Backup files 1.zip//C\Users\Brandi\AppData\Roaming\WildTangent\Updater\GameConsole\GameConsole-4.0.19.44-to-4.0.20.47.exe;Trojan-Ransom.NSIS.Onion.aaiq;Trojan program;07/19/2017 02:41:30
19.07.2017 02.41.11;Detected object (file) deleted;C:\DrFoneForAndroid\00020003;C:\DrFoneForAndroid\00020003;not-a-virus:HEUR:AdWare.AndroidOS.Yeahmobi.d;Adware;07/19/2017 02:41:11
19.07.2017 01.20.23;Detected object (email attachment) not processed;C:\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\Inbox\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/04/19 09:14:58]//FedEx-Parcel-ID-HFJ7RHAR.zip//FedEx-Parcel-ID-HFJ7RHAR/FedEx-Parcel-ID-HFJ7RHAR.doc.js;C:\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\Inbox\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/04/19 09:14:58]//FedEx-Parcel-ID-HFJ7RHAR.zip//FedEx-Parcel-ID-HFJ7RHAR/FedEx-Parcel-ID-HFJ7RHAR.doc.js;HEUR:Trojan.Script.Agent.gen;Trojan program;07/19/2017 01:20:23
18.07.2017 22.37.46;Detected object (email attachment) not processed;\\AIRWORX2-PC\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\Inbox\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/04/19 09:14:58]//FedEx-Parcel-ID-HFJ7RHAR.zip//FedEx-Parcel-ID-HFJ7RHAR/FedEx-Parcel-ID-HFJ7RHAR.doc.js;\\AIRWORX2-PC\Users\AIRWORX 2\AppData\Local\Microsoft\Outlook\[email protected]//[email protected]\Top of Outlook data file\Inbox\[From:[email protected]][Subject:Parcel Delivery Notification][Time:2017/04/19 09:14:58]//FedEx-Parcel-ID-HFJ7RHAR.zip//FedEx-Parcel-ID-HFJ7RHAR/FedEx-Parcel-ID-HFJ7RHAR.doc.js;HEUR:Trojan.Script.Agent.gen;Trojan program;07/18/2017 22:37:46
14.07.2017 04.01.56;Vulnerable object (file) detected;C:\Program Files (x86)\iTunes\iTunes.exe;C:\Program Files (x86)\iTunes\iTunes.exe;11013;Vulnerability;07/14/2017 04:01:56
14.07.2017 04.01.54;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}\7z.exe;10915;Vulnerability;07/14/2017 04:01:54
14.07.2017 04.01.52;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{39337565-330E-4ab6-A9AE-AC81E0720B10}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{39337565-330E-4ab6-A9AE-AC81E0720B10}\7z.exe;10915;Vulnerability;07/14/2017 04:01:52
14.07.2017 04.01.51;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}\7z.exe;10915;Vulnerability;07/14/2017 04:01:51
14.07.2017 04.01.50;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\7z.exe;10915;Vulnerability;07/14/2017 04:01:50
14.07.2017 03.58.18;Vulnerable object (file) detected;C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe;C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe;10773;Vulnerability;07/14/2017 03:58:18
14.07.2017 03.58.15;Vulnerable object (file) detected;C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe;C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe;10992;Vulnerability;07/14/2017 03:58:15
14.07.2017 03.51.59;Vulnerable object (file) detected;C:\Program Files\7-Zip\7z.exe;C:\Program Files\7-Zip\7z.exe;10915;Vulnerability;07/14/2017 03:51:59

 

I'll wait to hear from you, before I do the above. THX
 


  • 0

#45
RKinner

RKinner

    Malware Expert

  • Expert
  • 19,725 posts
  • MVP

I wouldn't worry about the vulnerable file detections:

 

14.07.2017 04.01.56;Vulnerable object (file) detected;C:\Program Files (x86)\iTunes\iTunes.exe;C:\Program Files (x86)\iTunes\iTunes.exe;11013;Vulnerability;07/14/2017 04:01:56
14.07.2017 04.01.54;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}\7z.exe;10915;Vulnerability;07/14/2017 04:01:54
14.07.2017 04.01.52;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{39337565-330E-4ab6-A9AE-AC81E0720B10}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{39337565-330E-4ab6-A9AE-AC81E0720B10}\7z.exe;10915;Vulnerability;07/14/2017 04:01:52
14.07.2017 04.01.51;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}\7z.exe;10915;Vulnerability;07/14/2017 04:01:51
14.07.2017 04.01.50;Vulnerable object (file) detected;C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\7z.exe;C:\Program Files (x86)\InstallShield Installation Information\{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}\7z.exe;10915;Vulnerability;07/14/2017 04:01:50
14.07.2017 03.58.18;Vulnerable object (file) detected;C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe;C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe;10773;Vulnerability;07/14/2017 03:58:18
14.07.2017 03.58.15;Vulnerable object (file) detected;C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe;C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe;10992;Vulnerability;07/14/2017 03:58:15
14.07.2017 03.51.59;Vulnerable object (file) detected;C:\Program Files\7-Zip\7z.exe;C:\Program Files\7-Zip\7z.exe;10915;Vulnerability;07/14/2017 03:51:59

 

 

But the rest can go if Kaspersky hasn't already deleted it.


  • 0






Similar Topics


Also tagged with one or more of these keywords: Malware, unknown virus

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP