Thanks to all the people who donated and ensured the continued development of this software!
If you want to donate and keep this software alive, please have a look at the About-Tab.
Thanks in advance!

USEC Radix V1, 0, 0, 11 [2010/02/09] at your service.
---- Check started at 17.4.2010 1:11:45 ----
Running on: Microsoft Windows NT 5.1 Build 2600 Service Pack 2
Number of Processors: 1, Active Processor Mask: 00000001
Processor: Intel Level 15 Revision 0103
Allocation granularity: 00010000, Page granularity: 00001000
Application space: 00010000-7FFEFFFF
Kernel Membase: 80000000
[X] Filter common false alarms.
1:11:45 - Performing check: "Hidden files":
This check can take some time depending on your harddisk size. You can interrupt it with the ESC key.
1:11:55 - Performing check: "Alternate Data Streams":
This check can take some time depending on your harddisk size. You can interrupt it with the ESC key.
[*]  C:\Documents and Settings\All Users\Application Data\Kaspersky Lab\AVP9\Data:extended:$DATA
[*]  C:\Documents and Settings\All Users\Application Data\TEMP:A8ADE5D8:$DATA
[*]  C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2:$DATA
[*]  C:\Documents and Settings\All Users\Documents\My Music\Sample Music\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\All Users\Documents\My Pictures\Sample Pictures\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Application Data\Microsoft\Internet Explorer\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Desktop\Guitar\Basic Guitar Chords  Beginner.url:favicon:$DATA
[*]  C:\Documents and Settings\John\Desktop\Guitar\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Desktop\RootsWeb's WorldConnect Project Kelley Genealogy.url:favicon:$DATA
[*]  C:\Documents and Settings\John\Desktop\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Desktop\trowbridge\New Folder (2)\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Desktop\trowbridge\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\John\Favorites\Windows XP Security Software Providers.url:favicon:$DATA
[*]  C:\Documents and Settings\Maddie\Desktop\Club Penguin.url:favicon:$DATA
[*]  C:\Documents and Settings\Maddie\Desktop\Email-login.url:favicon:$DATA
[*]  C:\Documents and Settings\Maddie\Desktop\Welcome to Webkinz - a Ganz website.url:favicon:$DATA
[*]  C:\Documents and Settings\Pam\Desktop\2010 Calendar.url:favicon:$DATA
[*]  C:\Documents and Settings\Pam\Desktop\Sign into FoodsDatabase.url:favicon:$DATA
[*]  C:\Documents and Settings\Pam\Desktop\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Pam\Desktop\WDIVweather.url:favicon:$DATA
[*]  C:\Documents and Settings\Pamela\Favorites\Links\Suggested Sites.url:favicon:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Adventure Quest Worlds.url:favicon:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Animals\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Bionicle Pictures\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Club Penguin .url:favicon:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Club Penguin Wallpaper\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Detroit Free Press.url:favicon:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Flags\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\geography\cavemen\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\geography\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Pokemon Cards\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Pokemon Shiny\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Science\Thumbs.db:encryptable:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\The 39 Clues.url:favicon:$DATA
[*]  C:\Documents and Settings\Sean\Desktop\Thumbs.db:encryptable:$DATA
[*]  C:\FTW\Thumbs.db:encryptable:$DATA
[-] Error scanning file C:\pagefile.sys: 0x05::0x06: The process cannot access the file because it is being used by another process.

[*]  C:\Program Files\Acoustica Mixcraft 4\mixrez\icons\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Acoustica Mixcraft 4\mixrez\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\ar.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\he.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\ko.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\paddle\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\pushpin\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\ru.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\shapes\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\zh-Hans.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Google\Google Earth\res\zh-Hant.locale\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\LEGO Company\LEGO Digital Designer\Help\de-manual\images\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\LEGO Company\LEGO Digital Designer\Help\en-manual\images\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\LiveUpdate\Engine\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\LiveUpdate\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Custom\MOTO_500\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Custom\MOTO_835\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Custom\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\media\Images\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\media\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Samples\Frames\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Samples\Images\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Skins\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\mobile PhoneTools\widcomm\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\NickOnline\Big Green Help\game\Textures\Thumbs.db:encryptable:$DATA
[*]  C:\Program Files\Windows Media Player\Network Sharing\Thumbs.db:encryptable:$DATA
[*]  C:\WINDOWS\SoftwareDistribution\Download\cf8ec753e88561d2ddb53e183dc05c3e\Thumbs.db:encryptable:$DATA
[*]  C:\WINDOWS\Thumbs.db:encryptable:$DATA
[*]  C:\WINDOWS\Web\printers\images\Thumbs.db:encryptable:$DATA
[*]  C:\WINDOWS\Web\Thumbs.db:encryptable:$DATA
[*]  C:\WINDOWS\Web\Wallpaper\Thumbs.db:encryptable:$DATA

69 streams found.
1:22:9 - Performing check: "Hidden processes":
(01) PID: 0 [00000000] (Idle)
(53) PID: 4 [86FC6660] (System)
(191) PID: 132 [868DB4F0] (hpwuSchd2.exe)
(191) PID: 200 [8659CB60] (hpqimzone.exe)
(175) PID: 244 [868E8460] (KHALMNPR.exe)
(175) PID: 328 [869169F0] (spoolsv.exe)
(191) PID: 528 [86A29DA0] (explorer.exe)
(191) PID: 744 [86BFBBE8] (avp.exe)
[*] The start address of thread 756 [ETHREAD: 865B0948 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810675. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810675: C0000008

[*] The start address of thread 768 [ETHREAD: 86524908 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 784 [ETHREAD: 864CD678 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 1776 [ETHREAD: 86B61020 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 228 [ETHREAD: 869B19A8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2288 [ETHREAD: 864ECBE8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2812 [ETHREAD: 8660D668 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2856 [ETHREAD: 86C49658 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2888 [ETHREAD: 8642B8E0 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2968 [ETHREAD: 8652BDA8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3016 [ETHREAD: 86441418 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3088 [ETHREAD: 8641CDA8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3224 [ETHREAD: 86405DA8 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3228 [ETHREAD: 86405B30 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3268 [ETHREAD: 86445020 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3272 [ETHREAD: 863DA908 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3280 [ETHREAD: 86C45910 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3312 [ETHREAD: 863FFB78 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3344 [ETHREAD: 863C7020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3348 [ETHREAD: 863CE020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3352 [ETHREAD: 8640B8E0 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3360 [ETHREAD: 863C9B30 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3416 [ETHREAD: 863B9020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3448 [ETHREAD: 86257020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3456 [ETHREAD: 86395908 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3572 [ETHREAD: 86256DA8 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3680 [ETHREAD: 86360DA8 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3696 [ETHREAD: 86364020 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3292 [ETHREAD: 861CF630 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2552 [ETHREAD: 861D1020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3300 [ETHREAD: 861BB020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3304 [ETHREAD: 861BC020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3308 [ETHREAD: 861F78E0 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3164 [ETHREAD: 861D8B10 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3012 [ETHREAD: 861CF020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3376 [ETHREAD: 861C0588 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2732 [ETHREAD: 861C3440 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3384 [ETHREAD: 861E1DA8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3464 [ETHREAD: 861D2658 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3468 [ETHREAD: 861BBDA8 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3472 [ETHREAD: 86419DA8 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3476 [ETHREAD: 861D5898 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3488 [ETHREAD: 861D36E0 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3620 [ETHREAD: 861FF020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3704 [ETHREAD: 861EA908 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2028 [ETHREAD: 861AC020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3120 [ETHREAD: 8617F6B8 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 4012 [ETHREAD: 8607D468 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 4040 [ETHREAD: 86520B30 (37)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3396 [ETHREAD: 86086790 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3000 [ETHREAD: 85EDD020 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3516 [ETHREAD: 85467798 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 892 [ETHREAD: 85EEAB58 (53)] of process avp.exe (PID 744) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

(191) PID: 776 [869B9020] (mDNSResponder.exe)
(175) PID: 832 [86B130E8] (svchost.exe)
(191) PID: 864 [869BD468] (AppleMobileDeviceService.exe)
(07) PID: 936 [866756E8] (smss.exe)
(175) PID: 968 [866DB720] (igfxtray.exe)
(175) PID: 976 [8651EDA0] (hkcmd.exe)
(175) PID: 984 [869C5B50] (SOUNDMAN.EXE)
(175) PID: 992 [866939D8] (ltmsg.exe)
(191) PID: 1032 [869EE9C8] (csrss.exe)
(191) PID: 1056 [86678DA0] (winlogon.exe)
(191) PID: 1076 [865029A0] (InCD.exe)
(191) PID: 1100 [868E9C08] (services.exe)
(191) PID: 1112 [86674DA0] (lsass.exe)
(191) PID: 1156 [86013468] (iexplore.exe)
(175) PID: 1236 [866D4900] (PWRISOVM.EXE)
(191) PID: 1276 [86BE2770] (svchost.exe)
(191) PID: 1292 [866E1B50] (avp.exe)
[*] The start address of thread 1296 [ETHREAD: 86503678 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810675. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810675: C0000008

[*] The start address of thread 1468 [ETHREAD: 86541908 (37)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3800 [ETHREAD: 86233020 (37)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3804 [ETHREAD: 86233B58 (37)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 4072 [ETHREAD: 86227B30 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2216 [ETHREAD: 861D7690 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 1284 [ETHREAD: 861AFDA8 (37)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 3500 [ETHREAD: 860DADA8 (37)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2304 [ETHREAD: 85466020 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2872 [ETHREAD: 85F06020 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

[*] The start address of thread 2676 [ETHREAD: 85EEB6B8 (53)] of process avp.exe (PID 1292) doesn't point inside a process module.
It points at address 7C810669. This is suspicious. You can try to kill or suspend this thread.
Cannot read memory @7C810669: C0000008

(175) PID: 1300 [865711D0] (GrooveMonitor.exe)
(191) PID: 1316 [866C1A58] (AcctMgr.exe)
(191) PID: 1364 [8664A908] (svchost.exe)
(191) PID: 1404 [866C6DA0] (iTunesHelper.exe)
(191) PID: 1424 [866E4DA0] (ctfmon.exe)
(175) PID: 1456 [869E6B50] (acrotray.exe)
(191) PID: 1504 [86923DA0] (svchost.exe)
(175) PID: 1544 [86514430] (InCDsrv.exe)
(191) PID: 1624 [866C3B28] (hpqtra08.exe)
(191) PID: 1724 [8696C898] (svchost.exe)
(191) PID: 1812 [868E05C0] (SetPoint.exe)
(191) PID: 1852 [869239F0] (svchost.exe)
(175) PID: 1908 [86539DA0] (ONENOTEM.EXE)
(175) PID: 2008 [86B66020] (svchost.exe)
(191) PID: 2124 [869A1DA0] (jqs.exe)
(191) PID: 2188 [8651DDA0] (mdm.exe)
(191) PID: 2308 [868EEB50] (HPZipm12.exe)
(175) PID: 2408 [86A05940] (svchost.exe)
(191) PID: 2500 [869A2270] (symlcsvc.exe)
(175) PID: 2528 [865A57C8] (ViewpointService.exe)
(191) PID: 2692 [861FCDA0] (alg.exe)
(191) PID: 3332 [8642CB60] (iexplore.exe)
(187) PID: 3392 [85EDF020] (wuauclt.exe)
(191) PID: 3544 [85F561B8] (radixgui.exe)
(175) PID: 3876 [86459B60] (AluSchedulerSvc.exe)
(191) PID: 4076 [862127E0] (iPodService.exe)
1:22:21 - Performing check: "Selftest":
Doing a short selftest...
 -> Checking IAT

PID 3544  - C:\Documents and Settings\John\Desktop\radixgui.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ole32.dll           (774E0000 - 7761D000)
VERSION.dll         (77C00000 - 77C08000)
dbghelp.dll         (59A60000 - 59B01000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
wintrust.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
Secur32.dll         (77FE0000 - 77FF1000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
msctfime.ime        (755C0000 - 755EE000)
OLEAUT32.DLL        (77120000 - 771AB000)
Selftest complete.

1:22:25 - Performing check: "MBR":
Partition Table:
+----+-----+------Start------+--------End------+----------+----------+----+
| Nr | Act | Head Sect Track | Head Sect Track |  Offset  |  Length  | OS |
+----+-----+-----------------+-----------------+----------+----------+----+
| 1  |  Y  | 001   01  0000  | 254   63  0255  | 0000003F | 04E1EDEC | 07 |
| 2  |  N  | 000   01  0255  | 254   63  0255  | 04E1EE2B | 0DBF5DD5 | 0F |
| 3  |  N  | 000   00  0000  | 000   00  0000  | 00000000 | 00000000 | 00 |
| 4  |  N  | 000   00  0000  | 000   00  0000  | 00000000 | 00000000 | 00 |
+----+-----+-----------------+-----------------+----------+----------+----+
MBR seems to be OK.
1:22:26 - Performing check: "Patched modules":
Module information:

Idx Base     Size     Module           Service          Pre Sig Patched
000 804D7000 00214500 ntoskrnl.exe                      YES YESThe code of FsRtlCheckLockForReadAccess at 80503C29 (0) got patched. Here is the diff:
Address   New-Original
80503C29: E9 - 8B  
80503C2A: F6 - FF  
80503C2B: D7 - 55  
80503C2C: 95 - 8B  
80503C2D: 6C - EC  
--> JMP DWORD PTR DS:[ECE61424]
[i] Function FsRtlCheckLockForReadAccess was patched @80503C29 probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


The code of IoIsOperationSynchronous at 804E8752 (0) got patched. Here is the diff:
Address   New-Original
804E8752: E9 - 8B  
804E8753: 87 - FF  
804E8754: 90 - 55  
804E8755: 97 - 8B  
804E8756: 6C - EC  
--> JMP DWORD PTR DS:[ECE617DE]
[i] Function IoIsOperationSynchronous was patched @804E8752 probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES



001 806EC000 00020380 hal.dll                           YES YES
002 F7D16000 00002000 KDCOM.DLL                         YES YES
003 F7C26000 00003000 BOOTVID.dll                       YES YES
004 F77C7000 0002E000 ACPI.sys         ACPI             YES YES
005 F7D18000 00002000 WMILIB.SYS                        YES YES
006 F77B6000 00011000 pci.sys          PCI              YES YES
007 F7816000 00009000 isapnp.sys       isapnp           YES YES
008 F7DDE000 00001000 pciide.sys       PCIIde           YES YES
009 F7A96000 00007000 PCIIDEX.SYS                       YES YES
010 F7D1A000 00002000 intelide.sys     IntelIde         YES YES
011 F7826000 0000B000 MountMgr.sys     MountMgr         YES YES
012 F7797000 0001F000 ftdisk.sys       Ftdisk           YES YES
013 F7D1C000 00002000 dmload.sys       dmload           YES YES
014 F7771000 00026000 dmio.sys         dmio             YES YES
015 F7A9E000 00005000 PartMgr.sys      PartMgr          YES YES
016 F7836000 0000D000 VolSnap.sys      VolSnap          YES YES
017 F7759000 00018000 atapi.sys        atapi            YES YES
018 F7743000 00016000 si3112.sys       si3112           YES YES
019 F772B000 00018000 SCSIPORT.SYS     ScsiPort         YES YES
020 F7846000 00009000 disk.sys         Disk             YES YES
021 F7856000 0000D000 CLASSPNP.SYS                      YES YES
022 F770B000 00020000 fltmgr.sys       FltMgr           YES YES
023 F76F9000 00012000 sr.sys           sr               YES YES
024 F7866000 0000B000 klbg.sys         klbg             YES YES
025 F7C2A000 00004000 SiWinAcc.sys     SiFilter         YES YES
026 F7876000 00009000 PxHelp20.sys     PxHelp20         YES YES
027 F76E2000 00017000 KSecDD.sys       KSecDD           YES YES
028 F76CF000 00013000 WudfPf.sys       WudfPf           YES YES
029 F7642000 0008D000 Ntfs.sys         Ntfs             YES YES
030 F7615000 0002D000 NDIS.sys         NDIS             YES YES
031 F7AA6000 00008000 SiRemFil.sys     SiRemFil         YES YES
032 F75FA000 0001B000 Mup.sys          Mup              YES YES
033 F70DA000 00520000 kl1.sys          kl1              YES YES
034 F7AAE000 00005000 TDI.SYS                           YES YES
035 F5A04000 000C6000 ialmnt5.sys      ialm             YES YES
036 F59F0000 00014000 VIDEOPRT.SYS                      YES YES
037 F7B56000 00005000 usbuhci.sys      usbuhci          YES YES
038 F59CD000 00023000 USBPORT.SYS                       YES YES
039 F7B5E000 00007000 usbehci.sys      usbehci          YES YES
040 F5932000 0009B000 ltmdmnt.sys      ltmodem5         YES YES
041 F7B66000 00008000 Modem.SYS        Modem            YES YES
042 F590F000 00023000 e100b325.sys     E100B            YES YES
043 F66E1000 0000D000 cdrom.sys        Cdrom            YES YES
044 F66D1000 0000F000 redbook.sys      redbook          YES YES
045 F58EC000 00023000 ks.sys                            YES YES
046 F7B6E000 00007000 InCDPass.sys     InCDPass         YES NO 
047 F7B76000 00007000 incdrm.SYS       incdrm           YES NO 
048 F7B7E000 00006000 GEARAspiWDM.sys  GEARAspiWDM      YES YES
049 F66C1000 0000B000 imapi.sys        Imapi            YES YES
050 F58A3000 00049000 ALCXWDM.SYS      ALCXWDM          YES NO 
051 F587F000 00024000 portcls.sys                       YES YES
052 F66B1000 0000F000 drmk.sys                          YES YES
053 F7B86000 00007000 fdc.sys          Fdc              YES YES
054 F66A1000 00010000 serial.sys       Serial           YES YES
055 F7CF6000 00004000 serenum.sys      serenum          YES YES
056 F586B000 00014000 parport.sys      Parport          YES YES
057 F7CFA000 00003000 gameenum.sys     gameenum         YES YES
058 F7E74000 00001000 msmpu401.sys     ms_mpu401        YES YES
059 F6691000 0000A000 klim5.sys        klim5            YES YES
060 F7E75000 00001000 audstub.sys      audstub          YES YES
061 F6681000 0000D000 rasl2tp.sys      Rasl2tp          YES YES
062 F5AEE000 00003000 ndistapi.sys     NdisTapi         YES YES
063 F5854000 00017000 ndiswan.sys      NdisWan          YES YES
064 F6671000 0000B000 raspppoe.sys     RasPppoe         YES YES
065 F78A6000 0000C000 raspptp.sys      PptpMiniport     YES YES
066 F5843000 00011000 psched.sys       PSched           YES YES
067 F78C6000 00009000 msgpc.sys        Gpc              YES YES
068 F7B8E000 00005000 ptilink.sys      Ptilink          YES YES
069 F7B96000 00005000 raspti.sys       Raspti           YES YES
070 F4FC4000 00031000 rdpdr.sys        rdpdr            YES YES
071 F78D6000 0000A000 termdd.sys       TermDD           YES YES
072 F7B9E000 00006000 kbdclass.sys     Kbdclass         YES YES
073 F7BA6000 00006000 mouclass.sys     Mouclass         YES YES
074 F7D70000 00002000 swenum.sys       swenum           YES YES
075 F4F6B000 00059000 update.sys       Update           YES YES
076 F5AD6000 00004000 mssmbios.sys     mssmbios         YES YES
077 F78F6000 0000A000 NDProxy.SYS      NDProxy          YES YES
078 F7906000 0000F000 usbhub.sys       usbhub           YES YES
079 F7D72000 00002000 USBD.SYS                          YES YES
080 F7BB6000 00005000 flpydisk.sys     Flpydisk         YES YES
081 ECE4D000 0004E000 klif.sys         KLIF             YES YES
082 F7BBE000 00008000 usbccgp.sys      usbccgp          YES YES
083 F7CAE000 00003000 hidusb.sys       HidUsb           YES YES
084 F7926000 00009000 HIDCLASS.SYS                      YES YES
085 F7BC6000 00007000 HIDPARSE.SYS                      YES YES
086 F7BCE000 00008000 LHidFilt.Sys     LHidFilt         YES YES
087 F7936000 0000D000 WDFLDR.SYS                        YES YES
088 F7D76000 00002000 Fs_Rec.SYS       Fs_Rec           YES YES
089 ECE11000 00001000 Null.SYS         Null             YES YES
090 F7CB6000 00004000 kbdhid.sys       kbdhid           YES YES
091 F7BDE000 00006000 vga.sys          VgaSave          YES YES
092 F7D78000 00002000 mnmdd.SYS        mnmdd            YES YES
093 F7D7A000 00002000 RDPCDD.sys       RDPCDD           YES YES
094 F7D7C000 00002000 InCDrec.SYS      InCDrec          YES NO 
095 ECD94000 00017000 InCDfs.SYS       InCDfs           YES NO 
096 F7BE6000 00005000 Msfs.SYS         Msfs             YES YES
097 F7BEE000 00008000 Npfs.SYS         Npfs             YES YES
098 F7CBA000 00003000 rasacd.sys       RasAcd           YES YES
099 ECD81000 00013000 ipsec.sys        IPSec            YES YES
100 ECD01000 00058000 tcpip.sys        Tcpip            YES YES
101 ECC86000 0007B000 Wdf01000.sys     Wdf01000         YES YES
102 ECC5E000 00028000 netbt.sys        NetBT            YES YES
103 ECC3C000 00022000 afd.sys          AFD              YES YES
104 F7966000 00009000 netbios.sys      NetBIOS          YES YES
105 F7BF6000 00008000 SCDEmu.SYS       SCDEmu           YES NO 
106 ECBE9000 0002B000 rdbss.sys        Rdbss            YES YES
107 ECB7A000 0006F000 mrxsmb.sys       MRxSmb           YES YES
108 F7976000 00009000 Fips.SYS         Fips             YES YES
109 ECB59000 00021000 ipnat.sys        IpNat            YES YES
110 F79C6000 00009000 wanarp.sys       Wanarp           YES YES
111 ECEBB000 00003000 mouhid.sys       mouhid           YES YES
112 F79B6000 00010000 Cdfs.SYS         Cdfs             YES YES
113 F7ACE000 00008000 LMouFilt.Sys     LMouFilt         YES YES
114 F79E6000 00009000 klmouflt.sys     klmouflt         YES YES
115 ECA79000 00018000 dump_atapi.sys                    NO  NO 
116 F7DA6000 00002000 dump_WMILIB.SYS                   NO  NO 
117 BF800000 001C4000 win32k.sys                        YES YES
118 ECD7D000 00003000 Dxapi.sys                         YES YES
119 F7AD6000 00005000 watchdog.sys                      YES YES
120 BF9C4000 00012000 dxg.sys                           YES YES
121 F7F0D000 00001000 dxgthk.sys                        YES YES
122 BF9E4000 0001F000 ialmdnt5.dll                      YES YES
123 BF9D6000 0000E000 ialmrnt5.dll                      YES YES
124 BFA03000 0002C000 ialmdev5.DLL                      YES YES
125 BFA2F000 000DD000 ialmdd5.DLL                       YES YES
126 BFFA0000 00046000 ATMFD.DLL                         YES YES
127 EC941000 00004000 ndisuio.sys      Ndisuio          YES YES
128 EC5DC000 00015000 wdmaud.sys       wdmaud           YES YES
129 ECB19000 0000F000 sysaudio.sys     sysaudio         YES YES
130 EC4C2000 0002C000 mrxdav.sys       MRxDAV           YES YES
131 F7D62000 00002000 ParVdm.SYS       ParVdm           YES YES
132 EBF98000 00052000 srv.sys          Srv              YES YES
133 F7B26000 00006000 symlcbrd.sys     symlcbrd         YES NO 
134 EB9A1000 00041000 HTTP.sys         HTTP             YES YES
135 F7B06000 00006000 TDTCP.SYS        TDTCP            YES YES
136 EB92E000 00023000 RDPWD.SYS        RDPWD            YES YES
137 EB56D000 00023000 Fastfat.SYS      Fastfat          YES YES
138 EC1EE000 00004000 sdthlpr.sys      SDTHelper        YES NO 
139 7C900000 000B2000 ntdll.dll                         YES YES

Number of Module Table entries patched = 1
1:25:13 - Performing check: "SDT hooks":
Found KiServiceTable @ 80559700

  0 ZwAcceptConnectPort                                   8057F37E 
  1 ZwAccessCheck                                         80578BFC 
  2 ZwAccessCheckAndAuditAlarm                            8058A82A 
  3 ZwAccessCheckByType                                   8058F860 
  4 ZwAccessCheckByTypeAndAuditAlarm                      8058F67A 
  5 ZwAccessCheckByTypeResultList                         80636886 
  6 ZwAccessCheckByTypeResultListAndAuditAlarm            80638A0F 
  7 ZwAccessCheckByTypeResultListAndAuditAlarmByHandle    80638A58 
  8 ZwAddAtom                                             8057467B 
  9 ZwAddBootEntry                                        806472AF 
 10 ZwAdjustGroupsToken                                   80636043 
 11 ZwAdjustPrivilegesToken                  --[HOOKED]-- ECE6C36E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 12 ZwAlertResumeThread                                   8062E188 
 13 ZwAlertThread                                         8057AEA1 
 14 ZwAllocateLocallyUniqueId                             8058BCA2 
 15 ZwAllocateUserPhysicalPages                           80625297 
 16 ZwAllocateUuids                                       805DBFA0 
 17 ZwAllocateVirtualMemory                               8056800D 
 18 ZwAreMappedFilesTheSame                               805D8B41 
 19 ZwAssignProcessToJobObject                            805A1C30 
 20 ZwCallbackReturn                                      804E2CB4 
 21 ZwCancelDeviceWakeupRequest                           8064729B 
 22 ZwCancelIoFile                                        805C92AC 
 23 ZwCancelTimer                                         804EFE28 
 24 ZwClearEvent                                          805686B9 
 25 ZwClose                                  --[HOOKED]-- ECE6CA86  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 26 ZwCloseObjectAuditAlarm                               8058F06F 
 27 ZwCompactKeys                                         8064D2A1 
 28 ZwCompareTokens                                       8058E971 
 29 ZwCompleteConnectPort                                 805802A1 
 30 ZwCompressKey                                         8064D50F 
 31 ZwConnectPort                            --[HOOKED]-- ECE6D60C  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 32 ZwContinue                                            804E1FF2 
 33 ZwCreateDebugObject                                   80658266 
 34 ZwCreateDirectoryObject                               805A1FD8 
 35 ZwCreateEvent                            --[HOOKED]-- ECE6DB40  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 36 ZwCreateEventPair                                     80647900 
 37 ZwCreateFile                             --[HOOKED]-- ECE6CD78  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 38 ZwCreateIoCompletion                                  8058FC6B 
 39 ZwCreateJobObject                                     805AA976 
 40 ZwCreateJobSet                                        8062E633 
 41 ZwCreateKey                              --[HOOKED]-- ECE6B460  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 42 ZwCreateMailslotFile                                  805D8A32 
 43 ZwCreateMutant                           --[HOOKED]-- ECE6DA18  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 44 ZwCreateNamedPipeFile                    --[HOOKED]-- ECE6AD0A  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 45 ZwCreatePagingFile                                    805BAFC8 
 46 ZwCreatePort                             --[HOOKED]-- ECE6D8D4  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 47 ZwCreateProcess                                       805B0B24 
 48 ZwCreateProcessEx                                     80581EFE 
 49 ZwCreateProfile                                       80647F21 
 50 ZwCreateSection                          --[HOOKED]-- ECE6C102  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 51 ZwCreateSemaphore                        --[HOOKED]-- ECE6DC72  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 52 ZwCreateSymbolicLinkObject               --[HOOKED]-- ECE6F40E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 53 ZwCreateThread                           --[HOOKED]-- ECE6C886  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 54 ZwCreateTimer                                         8059C2EA 
 55 ZwCreateToken                                         805A82DD 
 56 ZwCreateWaitablePort                     --[HOOKED]-- ECE6D976  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 57 ZwDebugActiveProcess                                  806593E1 
 58 ZwDebugContinue                                       8065953B 
 59 ZwDelayExecution                                      8056581E 
 60 ZwDeleteAtom                                          80589E5A 
 61 ZwDeleteBootEntry                                     8064729B 
 62 ZwDeleteFile                                          805D7417 
 63 ZwDeleteKey                              --[HOOKED]-- ECE6BA20  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 64 ZwDeleteObjectAuditAlarm                              80638AB3 
 65 ZwDeleteValueKey                         --[HOOKED]-- ECE6BCF8  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 66 ZwDeviceIoControlFile                    --[HOOKED]-- ECE6D21C  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 67 ZwDisplayString                                       805BE6D9 
 68 ZwDuplicateObject                        --[HOOKED]-- ECE6F980  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 69 ZwDuplicateToken                                      8057E68A 
 70 ZwEnumerateBootEntries                                806472AF 
 71 ZwEnumerateKey                           --[HOOKED]-- ECE6BE3A  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 72 ZwEnumerateSystemEnvironmentValuesEx                  80647287 
 73 ZwEnumerateValueKey                      --[HOOKED]-- ECE6BEE4  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 74 ZwExtendSection                                       806240B8 
 75 ZwFilterToken                                         805B0307 
 76 ZwFindAtom                                            8058F9C4 
 77 ZwFlushBuffersFile                                    80589FD7 
 78 ZwFlushInstructionCache                               80576A5A 
 79 ZwFlushKey                                            8059A978 
 80 ZwFlushVirtualMemory                                  805DCF0E 
 81 ZwFlushWriteBuffer                                    80625AFB 
 82 ZwFreeUserPhysicalPages                               8062564C 
 83 ZwFreeVirtualMemory                                   80568938 
 84 ZwFsControlFile                          --[HOOKED]-- ECE6D016  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 85 ZwGetContextThread                                    805DFA2D 
 86 ZwGetDevicePowerState                                 8062A96F 
 87 ZwGetPlugPlayEvent                                    8059F88C 
 88 ZwGetWriteWatch                                       8053ACD5 
 89 ZwImpersonateAnonymousToken                           80597585 
 90 ZwImpersonateClientOfPort                             8058E3DD 
 91 ZwImpersonateThread                                   8057A91E 
 92 ZwInitializeRegistry                                  805A3021 
 93 ZwInitiatePowerAction                                 8062A73B 
 94 ZwIsProcessInJob                                      8062E4E7 
 95 ZwIsSystemResumeAutomatic                             8062A956 
 96 ZwListenPort                                          805AA406 
 97 ZwLoadDriver                             --[HOOKED]-- ECE6EEA6  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 98 ZwLoadKey                                --[HOOKED]-- ECE6B43C  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


 99 ZwLoadKey2                               --[HOOKED]-- ECE6B44E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


100 ZwLockFile                                            8058C4E2 
101 ZwLockProductActivationKeys                           805B04D7 
102 ZwLockRegistryKey                                     805D4053 
103 ZwLockVirtualMemory                                   805AF944 
104 ZwMakePermanentObject                                 805A0FBA 
105 ZwMakeTemporaryObject                                 805A11A7 
106 ZwMapUserPhysicalPages                                80624783 
107 ZwMapUserPhysicalPagesScatter                         80624C57 
108 ZwMapViewOfSection                                    805723DC 
109 ZwModifyBootEntry                                     8064729B 
110 ZwNotifyChangeDirectoryFile                           80591149 
111 ZwNotifyChangeKey                        --[HOOKED]-- ECE6C030  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


112 ZwNotifyChangeMultipleKeys                            80590F5B 
113 ZwOpenDirectoryObject                                 8057FFBF 
114 ZwOpenEvent                              --[HOOKED]-- ECE6DBE2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


115 ZwOpenEventPair                                       806479F1 
116 ZwOpenFile                               --[HOOKED]-- ECE6CB08  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


117 ZwOpenIoCompletion                                    80615177 
118 ZwOpenJobObject                                       8062E88B 
119 ZwOpenKey                                --[HOOKED]-- ECE6B604  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


120 ZwOpenMutant                             --[HOOKED]-- ECE6DAB0  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


121 ZwOpenObjectAuditAlarm                                8059E506 
122 ZwOpenProcess                            --[HOOKED]-- ECE6C56E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


123 ZwOpenProcessToken                                    8056C0B1 
124 ZwOpenProcessTokenEx                                  8056C2AA 
125 ZwOpenSection                            --[HOOKED]-- ECE6F438  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


126 ZwOpenSemaphore                          --[HOOKED]-- ECE6DD14  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


127 ZwOpenSymbolicLinkObject                              8057FE8B 
128 ZwOpenThread                             --[HOOKED]-- ECE6C492  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


129 ZwOpenThreadToken                                     8056BB4E 
130 ZwOpenThreadTokenEx                                   8056BABC 
131 ZwOpenTimer                                           80647827 
132 ZwPlugPlayControl                                     805996CE 
133 ZwPowerInformation                                    8059D2AC 
134 ZwPrivilegeCheck                                      8059B1F8 
135 ZwPrivilegeObjectAuditAlarm                           805DBE0F 
136 ZwPrivilegedServiceAuditAlarm                         805AA71A 
137 ZwProtectVirtualMemory                                80573125 
138 ZwPulseEvent                                          805A24C2 
139 ZwQueryAttributesFile                                 805704E3 
140 ZwQueryBootEntryOrder                                 806472AF 
141 ZwQueryBootOptions                                    806472AF 
142 ZwQueryDebugFilterState                               804F7C05 
143 ZwQueryDefaultLocale                                  80565F92 
144 ZwQueryDefaultUILanguage                              80580E09 
145 ZwQueryDirectoryFile                                  80573585 
146 ZwQueryDirectoryObject                                80586A2B 
147 ZwQueryEaFile                                         80615600 
148 ZwQueryEvent                                          8058003C 
149 ZwQueryFullAttributesFile                             805799F1 
150 ZwQueryInformationAtom                                805D6E40 
151 ZwQueryInformationFile                                805714EE 
152 ZwQueryInformationJobObject                           80582FE7 
153 ZwQueryInformationPort                                80621B83 
154 ZwQueryInformationProcess                             8056BCEC 
155 ZwQueryInformationThread                              805664E7 
156 ZwQueryInformationToken                               8056C81B 
157 ZwQueryInstallUILanguage                              8058071E 
158 ZwQueryIntervalProfile                                806483D3 
159 ZwQueryIoCompletion                                   80615238 
160 ZwQueryKey                               --[HOOKED]-- ECE6BF8E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


161 ZwQueryMultipleValueKey                  --[HOOKED]-- ECE6BBB6  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


162 ZwQueryMutant                                         80647D5A 
163 ZwQueryObject                                         80581740 
164 ZwQueryOpenSubKeys                                    8064CECA 
165 ZwQueryPerformanceCounter                             80566821 
166 ZwQueryQuotaInformationFile                           80615ECB 
167 ZwQuerySection                                        80579E09 
168 ZwQuerySecurityObject                                 8059B093 
169 ZwQuerySemaphore                                      80646B53 
170 ZwQuerySymbolicLinkObject                             8057FCFC 
171 ZwQuerySystemEnvironmentValue                         806472D7 
172 ZwQuerySystemEnvironmentValueEx                       80647274 
173 ZwQuerySystemInformation                              8057D802 
174 ZwQuerySystemTime                                     8058FB4C 
175 ZwQueryTimer                                          805908D3 
176 ZwQueryTimerResolution                                8058626F 
177 ZwQueryValueKey                          --[HOOKED]-- ECE6B8BC  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


178 ZwQueryVirtualMemory                                  8056C3A8 
179 ZwQueryVolumeInformationFile                          8056FEAB 
180 ZwQueueApcThread                         --[HOOKED]-- ECE6F128  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


181 ZwRaiseException                                      804E203A 
182 ZwRaiseHardError                                      8064688F 
183 ZwReadFile                                            80570148 
184 ZwReadFileScatter                                     805D9EEC 
185 ZwReadRequestData                                     8058E722 
186 ZwReadVirtualMemory                                   8057A5B5 
187 ZwRegisterThreadTerminatePort                         8057CC68 
188 ZwReleaseMutant                                       80565889 
189 ZwReleaseSemaphore                                    8058A50E 
190 ZwRemoveIoCompletion                                  805662E2 
191 ZwRemoveProcessDebug                                  806594B6 
192 ZwRenameKey                              --[HOOKED]-- ECE6BB34  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


193 ZwReplaceKey                             --[HOOKED]-- ECE6B0C2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


194 ZwReplyPort                              --[HOOKED]-- ECE6E09E  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


195 ZwReplyWaitReceivePort                   --[HOOKED]-- ECE6DF64  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


196 ZwReplyWaitReceivePortEx                              80569A1E 
197 ZwReplyWaitReplyPort                                  80621C62 
198 ZwRequestDeviceWakeup                                 8062A8E3 
199 ZwRequestPort                                         80589AA8 
200 ZwRequestWaitReplyPort                   --[HOOKED]-- ECE6EC30  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


201 ZwRequestWakeupLatency                                8062A6DC 
202 ZwResetEvent                                          8059C7D3 
203 ZwResetWriteWatch                                     8053B16A 
204 ZwRestoreKey                             --[HOOKED]-- ECE6B224  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


205 ZwResumeProcess                                       8062E128 
206 ZwResumeThread                           --[HOOKED]-- ECE6F860  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


207 ZwSaveKey                                --[HOOKED]-- ECE6AEC4  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


208 ZwSaveKeyEx                                           8064C25F 
209 ZwSaveMergedKeys                                      8064C331 
210 ZwSecureConnectPort                      --[HOOKED]-- ECE6D312  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


211 ZwSetBootEntryOrder                                   806472AF 
212 ZwSetBootOptions                                      806472AF 
213 ZwSetContextThread                       --[HOOKED]-- ECE6C984  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


214 ZwSetDebugFilterState                                 8065AFFE 
215 ZwSetDefaultHardErrorPort                             805D4DAF 
216 ZwSetDefaultLocale                                    805AE00D 
217 ZwSetDefaultUILanguage                                805ADFB4 
218 ZwSetEaFile                                           80615B4F 
219 ZwSetEvent                                            80568708 
220 ZwSetEventBoostPriority                               80574C2E 
221 ZwSetHighEventPair                                    80647CE5 
222 ZwSetHighWaitLowEventPair                             80647C09 
223 ZwSetInformationDebugObject                           80658E57 
224 ZwSetInformationFile                                  80576F0C 
225 ZwSetInformationJobObject                             805AAACA 
226 ZwSetInformationKey                                   8064C827 
227 ZwSetInformationObject                                80580643 
228 ZwSetInformationProcess                               8056BDBD 
229 ZwSetInformationThread                                80574816 
230 ZwSetInformationToken                    --[HOOKED]-- ECE6E5F2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


231 ZwSetIntervalProfile                                  80647EFF 
232 ZwSetIoCompletion                                     80576DC1 
233 ZwSetLdtEntries                                       8062D20B 
234 ZwSetLowEventPair                                     80647C7B 
235 ZwSetLowWaitHighEventPair                             80647B97 
236 ZwSetQuotaInformationFile                             80615EA3 
237 ZwSetSecurityObject                      --[HOOKED]-- ECE6EFA0  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


238 ZwSetSystemEnvironmentValue                           80647574 
239 ZwSetSystemEnvironmentValueEx                         80647274 
240 ZwSetSystemInformation                   --[HOOKED]-- ECE6F4C2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


241 ZwSetSystemPowerState                                 806658A7 
242 ZwSetSystemTime                                       806461D7 
243 ZwSetThreadExecutionState                             805DF79C 
244 ZwSetTimer                                            804E579B 
245 ZwSetTimerResolution                                  805DFE22 
246 ZwSetUuidSeed                                         805AA8C6 
247 ZwSetValueKey                            --[HOOKED]-- ECE6B744  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


248 ZwSetVolumeInformationFile                            806163E5 
249 ZwShutdownSystem                                      80645923 
250 ZwSignalAndWaitForSingleObject                        805172D9 
251 ZwStartProfile                                        80648168 
252 ZwStopProfile                                         80648321 
253 ZwSuspendProcess                         --[HOOKED]-- ECE6F5A6  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


254 ZwSuspendThread                          --[HOOKED]-- ECE6F6D2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


255 ZwSystemDebugControl                     --[HOOKED]-- ECE6EDD2  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


256 ZwTerminateJobObject                                  8062EA01 
257 ZwTerminateProcess                       --[HOOKED]-- ECE6C6EA  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


258 ZwTerminateThread                        --[HOOKED]-- ECE6C63C  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


259 ZwTestAlert                                           8057C675 
260 ZwTraceEvent                                          80545000 
261 ZwTranslateFilePath                                   806472C3 
262 ZwUnloadDriver                                        80618800 
263 ZwUnloadKey                                           8064C3F7 
264 ZwUnloadKeyEx                                         8064C5F4 
265 ZwUnlockFile                                          8058C642 
266 ZwUnlockVirtualMemory                                 80625B6F 
267 ZwUnmapViewOfSection                                  80571F61 
268 ZwVdmControl                                          805B7130 
269 ZwWaitForDebugEvent                                   80658BA0 
270 ZwWaitForMultipleObjects                              80565AD4 
271 ZwWaitForSingleObject                                 8056558A 
272 ZwWaitHighEventPair                                   80647B2D 
273 ZwWaitLowEventPair                                    80647AC3 
274 ZwWriteFile                                           805771B5 
275 ZwWriteFileGather                                     805D9B22 
276 ZwWriteRequestData                                    8058E90F 
277 ZwWriteVirtualMemory                     --[HOOKED]-- ECE6C7C8  probably by C:\WINDOWS\system32\DRIVERS\klif.sys
-------------------------------------------------------------------------------
Information for module klif.sys:
-------------------------------------------------------------------------------
Index:		81
Base address:	ECE4D000
Size:		0004E000
Flags:		09104000
Load count:	1
Imagename:	\SystemRoot\system32\DRIVERS\klif.sys
Name:		Kaspersky Anti-Virus 
Version:	8.3.0.256
Company:	Kaspersky Lab
File Version:	8.3.0.256 built by: WinDDK
Description:	Klif Mini-Filter [fre_wnet_x86]
Possible path:	C:\WINDOWS\system32\DRIVERS\klif.sys
Signed:		YES


278 ZwYieldExecution                                      804F8B8D 
279 ZwCreateKeyedEvent                                    805CB51D 
280 ZwOpenKeyedEvent                                      8058396C 
281 ZwReleaseKeyedEvent                                   806488F5 
282 ZwWaitForKeyedEvent                                   80648B90 
283 ZwQueryPortInformationProcess                         8062BCC3 

Number of Service Table entries hooked = 57
Number of Service Table entries patched = 0
1:25:54 - Performing check: "IDT hooks":
IDT offset in kernel: 0x04C7B5E4
IDT address: 0x8003F400 (phys.: 0x02E5F400)

INT#    SegType DPL ISR
000(00) IntG32   00  0008:804DF350
001(01) IntG32   00  0008:804DF4CB
002(02) TaskG32  00  0058:80551896
003(03) IntG32   03  0008:804DF89D
004(04) IntG32   03  0008:804DFA20
005(05) IntG32   00  0008:804DFB81
006(06) IntG32   00  0008:804DFD02
007(07) IntG32   00  0008:804E036A
008(08) TaskG32  00  0050:80551888
009(09) IntG32   00  0008:804E078F
010(0A) IntG32   00  0008:804E08AC
011(0B) IntG32   00  0008:804E09E9
012(0C) IntG32   00  0008:804E0C42
013(0D) IntG32   00  0008:804E0F38
014(0E) IntG32   00  0008:804E164F
015(0F) IntG32   00  0008:804E197C
016(10) IntG32   00  0008:804E1A99
017(11) IntG32   00  0008:804E1BCE
018(12) TaskG32  00  00A0:074CC044 (hooked)  
019(13) IntG32   00  0008:804E1D34
020(14) IntG32   00  0008:804E197C
021(15) IntG32   00  0008:804E197C
022(16) IntG32   00  0008:804E197C
023(17) IntG32   00  0008:804E197C
024(18) IntG32   00  0008:804E197C
025(19) IntG32   00  0008:804E197C
026(1A) IntG32   00  0008:804E197C
027(1B) IntG32   00  0008:804E197C
028(1C) IntG32   00  0008:804E197C
029(1D) IntG32   00  0008:804E197C
030(1E) IntG32   00  0008:804E197C
031(1F) IntG32   00  0008:806EDFD0
032(20) Not present
033(21) Not present
034(22) Not present
035(23) Not present
036(24) Not present
037(25) Not present
038(26) Not present
039(27) Not present
040(28) Not present
041(29) Not present
042(2A) IntG32   03  0008:804DEB92
043(2B) IntG32   03  0008:804DEC95
044(2C) IntG32   03  0008:804DEE34
045(2D) IntG32   03  0008:804DF77C
046(2E) IntG32   03  0008:804DE631
047(2F) IntG32   00  0008:804E197C
048(30) IntG32   00  0008:804DDCF0
049(31) IntG32   00  0008:804DDCFA
050(32) IntG32   00  0008:804DDD04
051(33) IntG32   00  0008:804DDD0E
052(34) IntG32   00  0008:804DDD18
053(35) IntG32   00  0008:804DDD22
054(36) IntG32   00  0008:804DDD2C
055(37) IntG32   00  0008:806ED728
056(38) IntG32   00  0008:804DDD40
057(39) IntG32   00  0008:804DDD4A
058(3A) IntG32   00  0008:804DDD54
059(3B) IntG32   00  0008:804DDD5E
060(3C) IntG32   00  0008:804DDD68
061(3D) IntG32   00  0008:806EEB70
062(3E) IntG32   00  0008:804DDD7C
063(3F) IntG32   00  0008:804DDD86
064(40) IntG32   00  0008:804DDD90
065(41) IntG32   00  0008:806EE9CC
066(42) IntG32   00  0008:804DDDA4
067(43) IntG32   00  0008:804DDDAE
068(44) IntG32   00  0008:804DDDB8
069(45) IntG32   00  0008:804DDDC2
070(46) IntG32   00  0008:804DDDCC
071(47) IntG32   00  0008:804DDDD6
072(48) IntG32   00  0008:804DDDE0
073(49) IntG32   00  0008:804DDDEA
074(4A) IntG32   00  0008:804DDDF4
075(4B) IntG32   00  0008:804DDDFE
076(4C) IntG32   00  0008:804DDE08
077(4D) IntG32   00  0008:804DDE12
078(4E) IntG32   00  0008:804DDE1C
079(4F) IntG32   00  0008:804DDE26
080(50) IntG32   00  0008:806ED800
081(51) IntG32   00  0008:804DDE3A
082(52) IntG32   00  0008:804DDE44
083(53) IntG32   00  0008:804DDE4E
084(54) IntG32   00  0008:804DDE58
085(55) IntG32   00  0008:804DDE62
086(56) IntG32   00  0008:804DDE6C
087(57) IntG32   00  0008:804DDE76
088(58) IntG32   00  0008:804DDE80
089(59) IntG32   00  0008:804DDE8A
090(5A) IntG32   00  0008:804DDE94
091(5B) IntG32   00  0008:804DDE9E
092(5C) IntG32   00  0008:804DDEA8
093(5D) IntG32   00  0008:804DDEB2
094(5E) IntG32   00  0008:804DDEBC
095(5F) IntG32   00  0008:804DDEC6
096(60) IntG32   00  0008:804DDED0
097(61) IntG32   00  0008:804DDEDA
098(62) IntG32   00  0008:86F449CC (hooked)  
099(63) IntG32   00  0008:8694ADD4 (hooked)  
100(64) IntG32   00  0008:804DDEF8
101(65) IntG32   00  0008:804DDF02
102(66) IntG32   00  0008:804DDF0C
103(67) IntG32   00  0008:804DDF16
104(68) IntG32   00  0008:804DDF20
105(69) IntG32   00  0008:804DDF2A
106(6A) IntG32   00  0008:804DDF34
107(6B) IntG32   00  0008:804DDF3E
108(6C) IntG32   00  0008:804DDF48
109(6D) IntG32   00  0008:804DDF52
110(6E) IntG32   00  0008:804DDF5C
111(6F) IntG32   00  0008:804DDF66
112(70) IntG32   00  0008:804DDF70
113(71) IntG32   00  0008:867B4B5C (hooked)  
114(72) IntG32   00  0008:804DDF84
115(73) IntG32   00  0008:868CD43C (hooked)  
116(74) IntG32   00  0008:804DDF98
117(75) IntG32   00  0008:804DDFA2
118(76) IntG32   00  0008:804DDFAC
119(77) IntG32   00  0008:804DDFB6
120(78) IntG32   00  0008:804DDFC0
121(79) IntG32   00  0008:804DDFCA
122(7A) IntG32   00  0008:804DDFD4
123(7B) IntG32   00  0008:804DDFDE
124(7C) IntG32   00  0008:804DDFE8
125(7D) IntG32   00  0008:804DDFF2
126(7E) IntG32   00  0008:804DDFFC
127(7F) IntG32   00  0008:804DE006
128(80) IntG32   00  0008:804DE010
129(81) IntG32   00  0008:804DE01A
130(82) IntG32   00  0008:86F4ADD4 (hooked)  
131(83) IntG32   00  0008:86FC9B3C (hooked)  
132(84) IntG32   00  0008:804DE038
133(85) IntG32   00  0008:804DE042
134(86) IntG32   00  0008:804DE04C
135(87) IntG32   00  0008:804DE056
136(88) IntG32   00  0008:804DE060
137(89) IntG32   00  0008:804DE06A
138(8A) IntG32   00  0008:804DE074
139(8B) IntG32   00  0008:804DE07E
140(8C) IntG32   00  0008:804DE088
141(8D) IntG32   00  0008:804DE092
142(8E) IntG32   00  0008:804DE09C
143(8F) IntG32   00  0008:804DE0A6
144(90) IntG32   00  0008:804DE0B0
145(91) IntG32   00  0008:804DE0BA
146(92) IntG32   00  0008:8694CDD4 (hooked)  
147(93) IntG32   00  0008:804DE0CE
148(94) IntG32   00  0008:8686B674 (hooked)  
149(95) IntG32   00  0008:804DE0E2
150(96) IntG32   00  0008:804DE0EC
151(97) IntG32   00  0008:804DE0F6
152(98) IntG32   00  0008:804DE100
153(99) IntG32   00  0008:804DE10A
154(9A) IntG32   00  0008:804DE114
155(9B) IntG32   00  0008:804DE11E
156(9C) IntG32   00  0008:804DE128
157(9D) IntG32   00  0008:804DE132
158(9E) IntG32   00  0008:804DE13C
159(9F) IntG32   00  0008:804DE146
160(A0) IntG32   00  0008:804DE150
161(A1) IntG32   00  0008:804DE15A
162(A2) IntG32   00  0008:804DE164
163(A3) IntG32   00  0008:804DE16E
164(A4) IntG32   00  0008:86910044 (hooked)  
165(A5) IntG32   00  0008:804DE182
166(A6) IntG32   00  0008:804DE18C
167(A7) IntG32   00  0008:804DE196
168(A8) IntG32   00  0008:804DE1A0
169(A9) IntG32   00  0008:804DE1AA
170(AA) IntG32   00  0008:804DE1B4
171(AB) IntG32   00  0008:804DE1BE
172(AC) IntG32   00  0008:804DE1C8
173(AD) IntG32   00  0008:804DE1D2
174(AE) IntG32   00  0008:804DE1DC
175(AF) IntG32   00  0008:804DE1E6
176(B0) IntG32   00  0008:804DE1F0
177(B1) IntG32   00  0008:86F954C4 (hooked)  
178(B2) IntG32   00  0008:8685C98C (hooked)  
179(B3) IntG32   00  0008:804DE20E
180(B4) IntG32   00  0008:86A9443C (hooked)  
181(B5) IntG32   00  0008:804DE222
182(B6) IntG32   00  0008:804DE22C
183(B7) IntG32   00  0008:804DE236
184(B8) IntG32   00  0008:804DE240
185(B9) IntG32   00  0008:804DE24A
186(BA) IntG32   00  0008:804DE254
187(BB) IntG32   00  0008:804DE25E
188(BC) IntG32   00  0008:804DE268
189(BD) IntG32   00  0008:804DE272
190(BE) IntG32   00  0008:804DE27C
191(BF) IntG32   00  0008:804DE286
192(C0) IntG32   00  0008:804DE290
193(C1) IntG32   00  0008:806ED984
194(C2) IntG32   00  0008:804DE2A4
195(C3) IntG32   00  0008:804DE2AE
196(C4) IntG32   00  0008:804DE2B8
197(C5) IntG32   00  0008:804DE2C2
198(C6) IntG32   00  0008:804DE2CC
199(C7) IntG32   00  0008:804DE2D6
200(C8) IntG32   00  0008:804DE2E0
201(C9) IntG32   00  0008:804DE2EA
202(CA) IntG32   00  0008:804DE2F4
203(CB) IntG32   00  0008:804DE2FE
204(CC) IntG32   00  0008:804DE308
205(CD) IntG32   00  0008:804DE312
206(CE) IntG32   00  0008:804DE31C
207(CF) IntG32   00  0008:804DE326
208(D0) IntG32   00  0008:804DE330
209(D1) IntG32   00  0008:806ECD34
210(D2) IntG32   00  0008:804DE344
211(D3) IntG32   00  0008:804DE34E
212(D4) IntG32   00  0008:804DE358
213(D5) IntG32   00  0008:804DE362
214(D6) IntG32   00  0008:804DE36C
215(D7) IntG32   00  0008:804DE376
216(D8) IntG32   00  0008:804DE380
217(D9) IntG32   00  0008:804DE38A
218(DA) IntG32   00  0008:804DE394
219(DB) IntG32   00  0008:804DE39E
220(DC) IntG32   00  0008:804DE3A8
221(DD) IntG32   00  0008:804DE3B2
222(DE) IntG32   00  0008:804DE3BC
223(DF) IntG32   00  0008:804DE3C6
224(E0) IntG32   00  0008:804DE3D0
225(E1) IntG32   00  0008:806EDF0C
226(E2) IntG32   00  0008:804DE3E4
227(E3) IntG32   00  0008:806EDC70
228(E4) IntG32   00  0008:804DE3F8
229(E5) IntG32   00  0008:804DE402
230(E6) IntG32   00  0008:804DE40C
231(E7) IntG32   00  0008:804DE416
232(E8) IntG32   00  0008:804DE420
233(E9) IntG32   00  0008:804DE42A
234(EA) IntG32   00  0008:804DE434
235(EB) IntG32   00  0008:804DE43E
236(EC) IntG32   00  0008:804DE448
237(ED) IntG32   00  0008:804DE452
238(EE) IntG32   00  0008:804DE459
239(EF) IntG32   00  0008:804DE460
240(F0) IntG32   00  0008:804DE467
241(F1) IntG32   00  0008:804DE46E
242(F2) IntG32   00  0008:804DE475
243(F3) IntG32   00  0008:804DE47C
244(F4) IntG32   00  0008:804DE483
245(F5) IntG32   00  0008:804DE48A
246(F6) IntG32   00  0008:804DE491
247(F7) IntG32   00  0008:804DE498
248(F8) IntG32   00  0008:804DE49F
249(F9) IntG32   00  0008:804DE4A6
250(FA) IntG32   00  0008:804DE4AD
251(FB) IntG32   00  0008:804DE4B4
252(FC) IntG32   00  0008:804DE4BB
253(FD) IntG32   00  0008:806EE464
254(FE) IntG32   00  0008:806EE604
255(FF) IntG32   00  0008:804DE4D0
1:26:9 - Performing check: "SYSENTER hook":
SYSENTER offset in kernel: 0x004076F0 (=0x804DE6F0)
SYSENTER EIP: 0008:804DE6F0  [OK]
1:26:9 - Performing check: "IAT hooks":

PID 936   - C:\WINDOWS\System32\smss.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)

PID 1032  - C:\WINDOWS\system32\csrss.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
CSRSRV.dll          (75B40000 - 75B4B000)
basesrv.dll         (75B50000 - 75B60000)
winsrv.dll          (75B60000 - 75BAB000)
GDI32.dll           (77F10000 - 77F58000)
KERNEL32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
sxs.dll             (75E90000 - 75F40000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
Apphelp.dll         (77B40000 - 77B62000)
VERSION.dll         (77C00000 - 77C08000)

PID 1056  - C:\WINDOWS\system32\winlogon.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
AUTHZ.dll           (776C0000 - 776D1000)
msvcrt.dll          (77C10000 - 77C68000)
CRYPT32.dll         (77A80000 - 77B14000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
MSASN1.dll          (77B20000 - 77B32000)
NDdeApi.dll         (75940000 - 75948000)
PROFMAP.dll         (75930000 - 7593A000)
NETAPI32.dll        (5B860000 - 5B8B4000)
USERENV.dll         (769C0000 - 76A73000)
PSAPI.DLL           (76BF0000 - 76BFB000)
REGAPI.dll          (76BC0000 - 76BCF000)
Secur32.dll         (77FE0000 - 77FF1000)
SETUPAPI.dll        (77920000 - 77A13000)
VERSION.dll         (77C00000 - 77C08000)
WINSTA.dll          (76360000 - 76370000)
WINTRUST.dll        (76C30000 - 76C5E000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
IMM32.DLL           (76390000 - 763AD000)
MSGINA.dll          (75970000 - 75A67000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
COMCTL32.dll        (5D090000 - 5D12A000)
ODBC32.dll          (74320000 - 7435D000)
comdlg32.dll        (763B0000 - 763F9000)
comctl32.dll        (773D0000 - 774D3000)
odbcint.dll         (20000000 - 20017000)
SHSVCS.dll          (776E0000 - 77703000)
sfc.dll             (76BB0000 - 76BB5000)
sfc_os.dll          (76C60000 - 76C8A000)
ole32.dll           (774E0000 - 7761D000)
Apphelp.dll         (77B40000 - 77B62000)
msctfime.ime        (755C0000 - 755EE000)
WINSCARD.DLL        (723D0000 - 723EC000)
WTSAPI32.dll        (76F50000 - 76F58000)
WINMM.dll           (76B40000 - 76B6D000)
uxtheme.dll         (5AD70000 - 5ADA8000)
cscdll.dll          (76600000 - 7661D000)
klogon.dll          (6D4B0000 - 6D4E6000)
LBTWlgn.dll         (10000000 - 10012000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
WlNotify.dll        (75950000 - 7596A000)
WINSPOOL.DRV        (73000000 - 73026000)
MPR.dll             (71B20000 - 71B32000)
LBTServ.dll         (014A0000 - 014C4000)
WgaLogon.dll        (014E0000 - 0151C000)
OLEAUT32.dll        (77120000 - 771AB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
sxs.dll             (75E90000 - 75F40000)
cscui.dll           (77A20000 - 77A74000)
msv1_0.dll          (77C70000 - 77C94000)
cryptdll.dll        (76790000 - 7679C000)
iphlpapi.dll        (76D60000 - 76D79000)
MPRAPI.dll          (76D40000 - 76D58000)
ACTIVEDS.dll        (77CC0000 - 77CF2000)
adsldpc.dll         (76E10000 - 76E35000)
ATL.DLL             (76B20000 - 76B31000)
rtutils.dll         (76E80000 - 76E8E000)
xpsp2res.dll        (01870000 - 01B35000)
wdmaud.drv          (72D20000 - 72D29000)
msacm32.drv         (72D10000 - 72D18000)
MSACM32.dll         (77BE0000 - 77BF5000)
midimap.dll         (77BD0000 - 77BD7000)

PID 1100  - C:\WINDOWS\system32\services.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
NCObjAPI.DLL        (5F770000 - 5F77C000)
MSVCP60.dll         (76080000 - 760E5000)
SCESRV.dll          (758E0000 - 75930000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
USERENV.dll         (769C0000 - 76A73000)
AUTHZ.dll           (776C0000 - 776D1000)
umpnpmgr.dll        (7DBA0000 - 7DBC1000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
secur32.dll         (77FE0000 - 77FF1000)
Apphelp.dll         (77B40000 - 77B62000)
eventlog.dll        (77B70000 - 77B81000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
PSAPI.DLL           (76BF0000 - 76BFB000)
wtsapi32.dll        (76F50000 - 76F58000)

PID 1112  - C:\WINDOWS\system32\lsass.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
LSASRV.dll          (75730000 - 757E4000)
MPR.dll             (71B20000 - 71B32000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
MSASN1.dll          (77B20000 - 77B32000)
msvcrt.dll          (77C10000 - 77C68000)
NETAPI32.dll        (5B860000 - 5B8B4000)
NTDSAPI.dll         (767A0000 - 767B3000)
DNSAPI.dll          (76F20000 - 76F47000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
WLDAP32.dll         (76F60000 - 76F8C000)
Secur32.dll         (77FE0000 - 77FF1000)
SAMLIB.dll          (71BF0000 - 71C03000)
SAMSRV.dll          (74440000 - 744AA000)
cryptdll.dll        (76790000 - 7679C000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
msprivs.dll         (20000000 - 2000E000)
kerberos.dll        (71CF0000 - 71D3B000)
msv1_0.dll          (77C70000 - 77C94000)
iphlpapi.dll        (76D60000 - 76D79000)
netlogon.dll        (744B0000 - 74515000)
w32time.dll         (767C0000 - 767EC000)
MSVCP60.dll         (76080000 - 760E5000)
schannel.dll        (767F0000 - 7681D000)
CRYPT32.dll         (77A80000 - 77B14000)
wdigest.dll         (7DFC0000 - 7DFD2000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
setupapi.dll        (77920000 - 77A13000)
scecli.dll          (74410000 - 7443E000)
ipsecsvc.dll        (743E0000 - 7440F000)
AUTHZ.dll           (776C0000 - 776D1000)
oakley.DLL          (75D90000 - 75E5E000)
WINIPSEC.DLL        (74370000 - 7437B000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
pstorsvc.dll        (743A0000 - 743AB000)
psbase.dll          (743C0000 - 743DB000)
dssenh.dll          (68100000 - 68124000)

PID 1276  - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
rpcss.dll           (76A80000 - 76AE4000)
Secur32.dll         (77FE0000 - 77FF1000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
termsrv.dll         (760F0000 - 76143000)
ICAAPI.dll          (74F70000 - 74F76000)
SETUPAPI.dll        (77920000 - 77A13000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
AUTHZ.dll           (776C0000 - 776D1000)
mstlsapi.dll        (75110000 - 7512F000)
ACTIVEDS.dll        (77CC0000 - 77CF2000)
adsldpc.dll         (76E10000 - 76E35000)
NETAPI32.dll        (5B860000 - 5B8B4000)
ATL.DLL             (76B20000 - 76B31000)
REGAPI.dll          (76BC0000 - 76BCF000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
rdpwsx.dll          (72460000 - 72478000)
WINSPOOL.DRV        (73000000 - 73026000)
Apphelp.dll         (77B40000 - 77B62000)
msi.dll             (7D1E0000 - 7D49E000)

PID 1364  - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
rpcss.dll           (76A80000 - 76AE4000)
Secur32.dll         (77FE0000 - 77FF1000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
xpsp2res.dll        (20000000 - 202C5000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
DNSAPI.dll          (76F20000 - 76F47000)
iphlpapi.dll        (76D60000 - 76D79000)
winrnr.dll          (76FB0000 - 76FB8000)
WLDAP32.dll         (76F60000 - 76F8C000)
mdnsNSP.dll         (16080000 - 160A5000)
rasadhlp.dll        (76FC0000 - 76FC6000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
msi.dll             (7D1E0000 - 7D49E000)

PID 1504  - C:\WINDOWS\System32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
xpsp2res.dll        (20000000 - 202C5000)
shsvcs.dll          (776E0000 - 77703000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
dhcpcsvc.dll        (76D80000 - 76D9E000)
DNSAPI.dll          (76F20000 - 76F47000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
iphlpapi.dll        (76D60000 - 76D79000)
Secur32.dll         (77FE0000 - 77FF1000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
wzcsvc.dll          (77620000 - 7768E000)
rtutils.dll         (76E80000 - 76E8E000)
WMI.dll             (76D30000 - 76D34000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
WTSAPI32.dll        (76F50000 - 76F58000)
ESENT.dll           (606B0000 - 607BD000)
ATL.DLL             (76B20000 - 76B31000)
rastls.dll          (76B70000 - 76B8F000)
CRYPTUI.dll         (754D0000 - 75550000)
WINTRUST.dll        (76C30000 - 76C5E000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00C10000 - 00C19000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
MPRAPI.dll          (76D40000 - 76D58000)
ACTIVEDS.dll        (77CC0000 - 77CF2000)
adsldpc.dll         (76E10000 - 76E35000)
SETUPAPI.dll        (77920000 - 77A13000)
RASAPI32.dll        (76EE0000 - 76F1C000)
rasman.dll          (76E90000 - 76EA2000)
TAPI32.dll          (76EB0000 - 76EDF000)
SCHANNEL.dll        (767F0000 - 7681D000)
WinSCard.dll        (723D0000 - 723EC000)
raschap.dll         (76BD0000 - 76BE4000)
msv1_0.dll          (77C70000 - 77C94000)
cryptdll.dll        (76790000 - 7679C000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
schedsvc.dll        (77300000 - 77332000)
NTDSAPI.dll         (767A0000 - 767B3000)
MSIDLE.DLL          (74F50000 - 74F55000)
audiosrv.dll        (708B0000 - 708BD000)
wkssvc.dll          (76E40000 - 76E63000)
qmgr.dll            (5B9F0000 - 5BA54000)
MPR.dll             (71B20000 - 71B32000)
SHFOLDER.dll        (76780000 - 76789000)
WINHTTP.dll         (4D4F0000 - 4D548000)
cryptsvc.dll        (76CE0000 - 76CF2000)
certcli.dll         (77B90000 - 77BC2000)
dmserver.dll        (74F90000 - 74F99000)
ersvc.dll           (74F80000 - 74F89000)
es.dll              (77710000 - 77754000)
pchsvc.dll          (74F40000 - 74F4C000)
hidserv.dll         (688E0000 - 688E9000)
HID.DLL             (688F0000 - 688F9000)
srvsvc.dll          (75090000 - 750AA000)
netman.dll          (77D00000 - 77D33000)
netshell.dll        (76400000 - 765A6000)
credui.dll          (76C00000 - 76C2E000)
WZCSAPI.DLL         (73030000 - 73040000)
seclogon.dll        (73D20000 - 73D28000)
srsvc.dll           (751A0000 - 751CE000)
POWRPROF.dll        (74AD0000 - 74AD8000)
sens.dll            (722D0000 - 722DD000)
winrnr.dll          (76FB0000 - 76FB8000)
trkwks.dll          (75070000 - 75089000)
mdnsNSP.dll         (16080000 - 160A5000)
browser.dll         (76DA0000 - 76DB5000)
wuauserv.dll        (50000000 - 50005000)
wmisvc.dll          (59490000 - 594B8000)
VSSAPI.DLL          (753E0000 - 7544D000)
Cabinet.dll         (75150000 - 75164000)
w32time.dll         (767C0000 - 767EC000)
MSVCP60.dll         (76080000 - 760E5000)
sfc.dll             (76BB0000 - 76BB5000)
sfc_os.dll          (76C60000 - 76C8A000)
ipnathlp.dll        (66460000 - 664B5000)
AUTHZ.dll           (776C0000 - 776D1000)
wscsvc.dll          (4C0A0000 - 4C0B7000)
msi.dll             (7D1E0000 - 7D49E000)
wbemcomn.dll        (75290000 - 752C7000)
wbemcore.dll        (762C0000 - 76345000)
esscli.dll          (75310000 - 7534F000)
FastProx.dll        (75690000 - 75706000)
Apphelp.dll         (77B40000 - 77B62000)
SXS.DLL             (75E90000 - 75F40000)
wmiutils.dll        (75020000 - 7503B000)
repdrvfs.dll        (75200000 - 7522E000)
comsvcs.dll         (76620000 - 7675C000)
colbact.DLL         (75130000 - 75144000)
MTXCLU.DLL          (750F0000 - 75103000)
WSOCK32.dll         (71AD0000 - 71AD9000)
CLUSAPI.DLL         (76D10000 - 76D21000)
RESUTILS.DLL        (750B0000 - 750C2000)
wmiprvsd.dll        (418A0000 - 41912000)
NCObjAPI.DLL        (5F770000 - 5F77C000)
wbemess.dll         (75390000 - 753D6000)
ncprov.dll          (5F740000 - 5F74E000)
upnp.dll            (76DE0000 - 76E03000)
SSDPAPI.dll         (74F00000 - 74F0C000)
rasadhlp.dll        (76FC0000 - 76FC6000)
wups2.dll           (50F00000 - 50F0D000)
netcfgx.dll         (755F0000 - 7568A000)
rasmans.dll         (7DF30000 - 7DF61000)
WINIPSEC.DLL        (74370000 - 7437B000)
tapisrv.dll         (733E0000 - 73420000)
PSAPI.DLL           (76BF0000 - 76BFB000)
rastapi.dll         (75880000 - 75891000)
unimdm.tsp          (57CC0000 - 57CF6000)
uniplat.dll         (72000000 - 72007000)
unimdmat.dll        (5B070000 - 5B084000)
modemui.dll         (61650000 - 61678000)
kmddsp.tsp          (57D40000 - 57D4B000)
ndptsp.tsp          (57D20000 - 57D30000)
ipconf.tsp          (57D50000 - 57D58000)
h323.tsp            (57D70000 - 57DB6000)
hidphone.tsp        (57D60000 - 57D6A000)
rasppp.dll          (72240000 - 72275000)
ntlsapi.dll         (724B0000 - 724B6000)
kerberos.dll        (71CF0000 - 71D3B000)
msxml3.dll          (74980000 - 74AA3000)
RASDLG.dll          (768D0000 - 76974000)
dssenh.dll          (68100000 - 68124000)
wuaueng.dll         (50040000 - 50219000)
WINSPOOL.DRV        (73000000 - 73026000)
mspatcha.dll        (600A0000 - 600AB000)
advpack.dll         (65000000 - 6502E000)
wbemsvc.dll         (74ED0000 - 74EDE000)

PID 1544  - C:\Program Files\Ahead\InCD\InCDsrv.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
VERSION.dll         (77C00000 - 77C08000)
SHLWAPI.dll         (77F60000 - 77FD6000)
msvcrt.dll          (77C10000 - 77C68000)
ole32.dll           (774E0000 - 7761D000)
IMM32.DLL           (76390000 - 763AD000)
AdvrCntr.dll        (10000000 - 100EB000)
OLEAUT32.dll        (77120000 - 771AB000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
COMCTL32.dll        (5D090000 - 5D12A000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00B30000 - 00B39000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
WINSPOOL.DRV        (73000000 - 73026000)
comdlg32.dll        (763B0000 - 763F9000)
comctl32.dll        (773D0000 - 774D3000)
DriveLocker.dll     (00BA0000 - 00BC3000)
incdshx.dll         (1C000000 - 1C01F000)
uxtheme.dll         (5AD70000 - 5ADA8000)

PID 1724  - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
wudfsvc.dll         (00660000 - 00670000)
SETUPAPI.dll        (77920000 - 77A13000)
WUDFPlatform.dll    (00670000 - 0069C000)
Secur32.dll         (77FE0000 - 77FF1000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)

PID 1852  - C:\WINDOWS\System32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
dnsrslvr.dll        (76770000 - 7677D000)
DNSAPI.dll          (76F20000 - 76F47000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
iphlpapi.dll        (76D60000 - 76D79000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)

PID 2008  - C:\WINDOWS\system32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
xpsp2res.dll        (20000000 - 202C5000)
lmhsvc.dll          (74C40000 - 74C46000)
iphlpapi.dll        (76D60000 - 76D79000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
regsvc.dll          (76AF0000 - 76B02000)
secur32.dll         (77FE0000 - 77FF1000)
ssdpsrv.dll         (765E0000 - 765F4000)
hnetcfg.dll         (662B0000 - 66308000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
mswsock.dll         (71A50000 - 71A8F000)
wshtcpip.dll        (71A90000 - 71A98000)

PID 328   - C:\WINDOWS\system32\spoolsv.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
msvcrt.dll          (77C10000 - 77C68000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
SPOOLSS.DLL         (742E0000 - 742F5000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
DNSAPI.dll          (76F20000 - 76F47000)
rasadhlp.dll        (76FC0000 - 76FC6000)
localspl.dll        (75BB0000 - 75C07000)
Secur32.dll         (77FE0000 - 77FF1000)
sfc_os.dll          (76C60000 - 76C8A000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
winspool.drv        (73000000 - 73026000)
netapi32.dll        (5B860000 - 5B8B4000)
AdobePDF.dll        (50400000 - 50409000)
adistres.dll        (65000000 - 65026000)
cnbjmon.dll         (742A0000 - 742AE000)
HpTcpMon.dll        (10000000 - 10028000)
hpzjrd01.dll        (00CF0000 - 00D15000)
CLUSAPI.dll         (76D10000 - 76D21000)
HPTcpMUI.dll        (00D20000 - 00D54000)
hptcpmib.dll        (00D80000 - 00D94000)
mgmtapi.dll         (72020000 - 72027000)
snmpapi.dll         (71F60000 - 71F68000)
wsnmp32.dll         (72010000 - 7201E000)
hpz3l3xu.dll        (00DC0000 - 00DCC000)
mdimon.dll          (00DD0000 - 00DD9000)
MSVCR80.dll         (78130000 - 781CB000)
msi.dll             (7D1E0000 - 7D49E000)
pjlmon.dll          (74280000 - 74287000)
msonpmon.dll        (00E00000 - 00E09000)
tcpmon.dll          (72400000 - 7240E000)
usbmon.dll          (723F0000 - 723F7000)
hpzpp3xu.dll        (00E60000 - 00E73000)
mdippr.dll          (00E80000 - 00E89000)
filterpipelineprintproc.dll(3F420000 - 3F43B000)
msonpppr.dll        (00EB0000 - 00EB9000)
mswsock.dll         (71A50000 - 71A8F000)
winrnr.dll          (76FB0000 - 76FB8000)
WLDAP32.dll         (76F60000 - 76F8C000)
mdnsNSP.dll         (16080000 - 160A5000)
Iphlpapi.dll        (76D60000 - 76D79000)
win32spl.dll        (75C10000 - 75C33000)
NETRAP.dll          (71C80000 - 71C87000)
NTDSAPI.dll         (767A0000 - 767B3000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
inetpp.dll          (74300000 - 74315000)
xpsp2res.dll        (20000000 - 202C5000)

PID 528   - C:\WINDOWS\Explorer.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
BROWSEUI.dll        (75F80000 - 7607D000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
msvcrt.dll          (77C10000 - 77C68000)
ole32.dll           (774E0000 - 7761D000)
SHLWAPI.dll         (77F60000 - 77FD6000)
OLEAUT32.dll        (77120000 - 771AB000)
SHDOCVW.dll         (77760000 - 778D0000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
CRYPTUI.dll         (754D0000 - 75550000)
WINTRUST.dll        (76C30000 - 76C5E000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
NETAPI32.dll        (5B860000 - 5B8B4000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00400000 - 00409000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
WLDAP32.dll         (76F60000 - 76F8C000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
UxTheme.dll         (5AD70000 - 5ADA8000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
MSACM32.dll         (77BE0000 - 77BF5000)
USERENV.dll         (769C0000 - 76A73000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
msctfime.ime        (755C0000 - 755EE000)
appHelp.dll         (77B40000 - 77B62000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
GrooveShellExtensions.dll(661D0000 - 663EF000)
GrooveUtil.DLL      (68EF0000 - 68FE2000)
MSVCR80.dll         (78130000 - 781CB000)
GrooveNew.DLL       (68FF0000 - 68FF7000)
ATL80.DLL           (7C630000 - 7C64B000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
MSImg32.dll         (76380000 - 76385000)
cscui.dll           (77A20000 - 77A74000)
CSCDLL.dll          (76600000 - 7661D000)
themeui.dll         (5BA60000 - 5BAD1000)
Secur32.dll         (77FE0000 - 77FF1000)
xpsp2res.dll        (20000000 - 202C5000)
actxprxy.dll        (71D40000 - 71D5C000)
wmpband.dll         (13420000 - 1343A000)
MPR.dll             (71B20000 - 71B32000)
SAMLIB.dll          (71BF0000 - 71C03000)
GrooveSystemServices.dll(65E50000 - 65E7D000)
msxml3.dll          (74980000 - 74AA3000)
LINKINFO.dll        (76980000 - 76988000)
ntshrui.dll         (76990000 - 769B5000)
ATL.DLL             (76B20000 - 76B31000)
SETUPAPI.dll        (77920000 - 77A13000)
msi.dll             (7D1E0000 - 7D49E000)
WINSTA.dll          (76360000 - 76370000)
webcheck.dll        (00E90000 - 00ECD000)
IEFRAME.dll         (01C40000 - 026D1000)
MLANG.dll           (75CF0000 - 75D81000)
stobject.dll        (76280000 - 762A1000)
BatMeter.dll        (74AF0000 - 74AFA000)
POWRPROF.dll        (74AD0000 - 74AD8000)
WTSAPI32.dll        (76F50000 - 76F58000)
WPDShServiceObj.dll (164A0000 - 164C3000)
WINHTTP.dll         (4D4F0000 - 4D548000)
mydocs.dll          (72410000 - 7242A000)
PortableDeviceTypes.dll(109C0000 - 109EC000)
PortableDeviceApi.dll(10930000 - 10979000)
NETSHELL.dll        (76400000 - 765A6000)
rtutils.dll         (76E80000 - 76E8E000)
credui.dll          (76C00000 - 76C2E000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
iphlpapi.dll        (76D60000 - 76D79000)
GrooveMisc.dll      (66B50000 - 66CCF000)
MSCTF.dll           (74720000 - 7476B000)
wdmaud.drv          (72D20000 - 72D29000)
lgscroll.dll        (10100000 - 1010E000)
NTMARTA.DLL         (77690000 - 776B1000)
msacm32.drv         (72D10000 - 72D18000)
midimap.dll         (77BD0000 - 77BD7000)
drprov.dll          (75F60000 - 75F67000)
ntlanman.dll        (71C10000 - 71C1E000)
NETUI0.dll          (71CD0000 - 71CE7000)
NETUI1.dll          (71C90000 - 71CD0000)
NETRAP.dll          (71C80000 - 71C87000)
davclnt.dll         (75F70000 - 75F79000)
rarext.dll          (00A60000 - 00A8E000)
PWRISOSH.DLL        (10000000 - 10037000)
comdlg32.dll        (763B0000 - 763F9000)
WINSPOOL.DRV        (73000000 - 73026000)
mbamext.dll         (00E30000 - 00E48000)
shellex.dll         (6D960000 - 6D978000)
MSVCP80.dll         (7C420000 - 7C4A7000)
prremote.dll        (6D900000 - 6D916000)
prloader.dll        (6D8D0000 - 6D8F7000)
syncui.dll          (74650000 - 74681000)
SXS.DLL             (75E90000 - 75F40000)
zipfldr.dll         (73380000 - 733D7000)
ContextMenu.dll     (02D70000 - 02DD5000)
MFC42.DLL           (73DD0000 - 73ECE000)
MSVCP60.dll         (76080000 - 760E5000)
browselc.dll        (01B60000 - 01B72000)
DUSER.dll           (6C1B0000 - 6C1FD000)

PID 832   - C:\WINDOWS\System32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
xpsp2res.dll        (20000000 - 202C5000)
webclnt.dll         (5A6E0000 - 5A6F5000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00660000 - 00669000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
Secur32.dll         (77FE0000 - 77FF1000)

PID 864   - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
msvcrt.dll          (77C10000 - 77C68000)
WS2HELP.dll         (71AA0000 - 71AA8000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SETUPAPI.dll        (77920000 - 77A13000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
WTSAPI32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
USERENV.dll         (769C0000 - 76A73000)
IMM32.DLL           (76390000 - 763AD000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
ole32.dll           (774E0000 - 7761D000)
SAMLIB.dll          (71BF0000 - 71C03000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)

PID 968   - C:\WINDOWS\system32\igfxtray.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
COMCTL32.dll        (5D090000 - 5D12A000)
hccutils.DLL        (10000000 - 1001E000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
uxtheme.dll         (5AD70000 - 5ADA8000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
VERSION.dll         (77C00000 - 77C08000)
igfxdev.dll         (00940000 - 00964000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
msctfime.ime        (755C0000 - 755EE000)
igfxsrvc.dll        (00A70000 - 00AC8000)
igfxres.dll         (00AE0000 - 00B09000)
igfxress.dll        (00B20000 - 00C51000)

PID 976   - C:\WINDOWS\system32\hkcmd.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
COMCTL32.dll        (5D090000 - 5D12A000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
hccutils.DLL        (10000000 - 1001E000)
IMM32.DLL           (76390000 - 763AD000)
uxtheme.dll         (5AD70000 - 5ADA8000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
VERSION.dll         (77C00000 - 77C08000)
igfxdev.dll         (00920000 - 00944000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
msctfime.ime        (755C0000 - 755EE000)
igfxsrvc.dll        (00A60000 - 00AB8000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
comctl32.dll        (773D0000 - 774D3000)
igfxhk.dll          (00AE0000 - 00B02000)
igfxres.dll         (00B20000 - 00B49000)

PID 984   - C:\WINDOWS\SOUNDMAN.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
SETUPAPI.dll        (77920000 - 77A13000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
uxtheme.dll         (5AD70000 - 5ADA8000)
msctfime.ime        (755C0000 - 755EE000)
ole32.dll           (774E0000 - 7761D000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)

PID 992   - C:\WINDOWS\LTMSG.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
WINMM.dll           (76B40000 - 76B6D000)
IMM32.DLL           (76390000 - 763AD000)
uxtheme.dll         (5AD70000 - 5ADA8000)
msvcrt.dll          (77C10000 - 77C68000)
msctfime.ime        (755C0000 - 755EE000)
ole32.dll           (774E0000 - 7761D000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)

PID 1076  - C:\Program Files\Ahead\InCD\InCD.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
InCDapi.dll         (10000000 - 10115000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
VERSION.dll         (77C00000 - 77C08000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
msvcrt.dll          (77C10000 - 77C68000)
COMCTL32.dll        (773D0000 - 774D3000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
WINSPOOL.DRV        (73000000 - 73026000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
IMM32.DLL           (76390000 - 763AD000)
uxtheme.dll         (5AD70000 - 5ADA8000)
SETUPAPI.dll        (77920000 - 77A13000)
msctfime.ime        (755C0000 - 755EE000)
DriveLocker.dll     (00F10000 - 00F33000)
incdshx.dll         (1C000000 - 1C01F000)
MSCTF.dll           (74720000 - 7476B000)
AdvrCntr.dll        (010F0000 - 011DB000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (011E0000 - 011E9000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
lgscroll.dll        (01430000 - 0143E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
wtsapi32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)

PID 132   - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
uxtheme.dll         (5AD70000 - 5ADA8000)
msctfime.ime        (755C0000 - 755EE000)
ole32.dll           (774E0000 - 7761D000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)

PID 1236  - C:\Program Files\PowerISO\PWRISOVM.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
WINSPOOL.DRV        (73000000 - 73026000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
ole32.dll           (774E0000 - 7761D000)
SAMLIB.dll          (71BF0000 - 71C03000)
msctfime.ime        (755C0000 - 755EE000)

PID 1300  - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ole32.dll           (774E0000 - 7761D000)
GrooveUtil.DLL      (68EF0000 - 68FE2000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00340000 - 00349000)
urlmon.dll          (1A400000 - 1A532000)
OLEAUT32.dll        (77120000 - 771AB000)
iertutil.dll        (5DCA0000 - 5DE88000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
MSVCR80.dll         (78130000 - 781CB000)
GrooveNew.DLL       (68FF0000 - 68FF7000)
VERSION.dll         (77C00000 - 77C08000)
ATL80.DLL           (7C630000 - 7C64B000)
COMCTL32.dll        (5D090000 - 5D12A000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
uxtheme.dll         (5AD70000 - 5ADA8000)
msctfime.ime        (755C0000 - 755EE000)
USERENV.dll         (769C0000 - 76A73000)
SETUPAPI.dll        (77920000 - 77A13000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
GrooveShellExtensions.dll(661D0000 - 663EF000)
MSImg32.dll         (76380000 - 76385000)
GrooveSystemServices.dll(65E50000 - 65E7D000)
lgscroll.dll        (10100000 - 1010E000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
MSCTF.dll           (74720000 - 7476B000)
LINKINFO.dll        (76980000 - 76988000)
ntshrui.dll         (76990000 - 769B5000)
ATL.DLL             (76B20000 - 76B31000)
NETAPI32.dll        (5B860000 - 5B8B4000)
msxml3.dll          (74980000 - 74AA3000)

PID 1316  - C:\Program Files\Norton Password Manager\AcctMgr.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
OLEACC.dll          (74C80000 - 74CAC000)
msvcrt.dll          (77C10000 - 77C68000)
MSVCP60.dll         (76080000 - 760E5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
msi.dll             (7D1E0000 - 7D49E000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
COMCTL32.dll        (773D0000 - 774D3000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
MSVCP70.dll         (7C080000 - 7C0F7000)
MSVCR70.dll         (7C000000 - 7C054000)
gdiplus.dll         (4EC50000 - 4EDFB000)
DINPUT.dll          (72280000 - 722AA000)
WINMM.dll           (76B40000 - 76B6D000)
SETUPAPI.dll        (77920000 - 77A13000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
IMM32.DLL           (76390000 - 763AD000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
VERSION.dll         (77C00000 - 77C08000)
msxml4.dll          (69B10000 - 69C5D000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (010C0000 - 010C9000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
Secur32.dll         (77FE0000 - 77FF1000)
uxtheme.dll         (5AD70000 - 5ADA8000)
xpsp2res.dll        (20000000 - 202C5000)
MSCTF.dll           (74720000 - 7476B000)
MSVCR80.dll         (78130000 - 781CB000)
PPW32HLP.dll        (10000000 - 10048000)
WinTrust.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
userenv.dll         (769C0000 - 76A73000)
netapi32.dll        (5B860000 - 5B8B4000)
lgscroll.dll        (10100000 - 1010E000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
msctfime.ime        (755C0000 - 755EE000)
SXS.DLL             (75E90000 - 75F40000)

PID 1404  - C:\Program Files\iTunes\iTunesHelper.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHLWAPI.dll         (77F60000 - 77FD6000)
msvcrt.dll          (77C10000 - 77C68000)
IMM32.DLL           (76390000 - 763AD000)
iTunesHelper.dll    (10000000 - 10037000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
CoreFoundation.dll  (00930000 - 009FA000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
MSVCR80.dll         (78130000 - 781CB000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
pthreadVC2.dll      (008B0000 - 008C0000)
WSOCK32.dll         (71AD0000 - 71AD9000)
objc.dll            (008C0000 - 008DC000)
MSVCP80.dll         (7C420000 - 7C4A7000)
icuin40.dll         (00A00000 - 00AFD000)
icuuc40.dll         (00B00000 - 00BE1000)
icudt40.dll         (4AD00000 - 4BA5B000)
ASL.dll             (00910000 - 0091D000)
VERSION.dll         (77C00000 - 77C08000)
SETUPAPI.dll        (77920000 - 77A13000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00C00000 - 00C09000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
comctl32.dll        (773D0000 - 774D3000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
Secur32.dll         (77FE0000 - 77FF1000)
iTunesHelperLocalized.DLL(01270000 - 0127E000)
iTunesHelper.DLL    (012A0000 - 012AE000)
msctfime.ime        (755C0000 - 755EE000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
QuickTime.qts       (66800000 - 673AB000)
QTCF.dll            (68A40000 - 68A6E000)
WINMM.dll           (76B40000 - 76B6D000)
comdlg32.dll        (763B0000 - 763F9000)
gdiplus.dll         (4EC50000 - 4EDFB000)
DSOUND.dll          (73F10000 - 73F6C000)
CFNetwork.DLL       (01800000 - 01893000)
SQLite3.dll         (018B0000 - 01913000)
zlib1.dll           (01930000 - 01943000)
iphlpapi.dll        (76D60000 - 76D79000)
ddraw.dll           (73760000 - 737A9000)
DCIMAN32.dll        (73BC0000 - 73BC6000)
lgscroll.dll        (10100000 - 1010E000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
iTunesMobileDevice.dll(099B0000 - 09AFF000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
Wtsapi32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
xpsp2res.dll        (20000000 - 202C5000)
msi.dll             (7D1E0000 - 7D49E000)
SXS.DLL             (75E90000 - 75F40000)

PID 1424  - C:\WINDOWS\system32\ctfmon.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
msvcrt.dll          (77C10000 - 77C68000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
MSCTF.dll           (74720000 - 7476B000)
MSUTB.dll           (5FC10000 - 5FC43000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
msctfime.ime        (755C0000 - 755EE000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)

PID 1456  - C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
WINSPOOL.DRV        (73000000 - 73026000)
COMCTL32.dll        (5D090000 - 5D12A000)
comdlg32.dll        (763B0000 - 763F9000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
msctfime.ime        (755C0000 - 755EE000)
ole32.dll           (774E0000 - 7761D000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)

PID 1624  - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
VERSION.dll         (77C00000 - 77C08000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
COMCTL32.dll        (5D090000 - 5D12A000)
MSVCP60.dll         (76080000 - 760E5000)
IMM32.DLL           (76390000 - 763AD000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
msctfime.ime        (755C0000 - 755EE000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
hpqcxm08.dll        (14A00000 - 14A23000)
SHLWAPI.dll         (77F60000 - 77FD6000)
SHFOLDER.dll        (76780000 - 76789000)
WTSAPI32.DLL        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
msi.dll             (7D1E0000 - 7D49E000)
hpquio08.dll        (14000000 - 14019000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
comctl32.dll        (773D0000 - 774D3000)
hpqtra08.rsc        (15000000 - 15010000)
hpqtao08.dll        (15800000 - 15810000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
SXS.DLL             (75E90000 - 75F40000)
hpqrif08.dll        (10000000 - 10039000)
hpqmif08.dll        (00E50000 - 00E8B000)
hpotra08.dll        (16600000 - 16633000)
WINSPOOL.DRV        (73000000 - 73026000)
SETUPAPI.dll        (77920000 - 77A13000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
CFGMGR32.dll        (74AE0000 - 74AE7000)
hpotra08.rsc        (16750000 - 16757000)
hpotradd.dll        (00EA0000 - 00EAD000)
hpodvd09.dll        (3AB00000 - 3AB14000)
hpoddcomm09.dll     (3AF00000 - 3AF19000)
hpqusg.dll          (010B0000 - 010FD000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (01100000 - 01109000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
hpodio08.dll        (14400000 - 144AA000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
Apphelp.dll         (77B40000 - 77B62000)

PID 1812  - C:\Program Files\Logitech\SetPoint\SetPoint.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
VERSION.dll         (77C00000 - 77C08000)
WINMM.dll           (76B40000 - 76B6D000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
KemUtil.dll         (10700000 - 10728000)
MFC80U.DLL          (782E0000 - 783EF000)
MSVCR80.dll         (78130000 - 781CB000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
comdlg32.dll        (763B0000 - 763F9000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
MSVCP80.dll         (7C420000 - 7C4A7000)
SetPointCOM.dll     (12A00000 - 12A0A000)
kemutb.dll          (10800000 - 1082A000)
KemWnd.dll          (10B00000 - 10B1B000)
MSIMG32.dll         (76380000 - 76385000)
gdiplus.dll         (4EC50000 - 4EDFB000)
KemXML.dll          (10900000 - 10913000)
lgscroll.dll        (10100000 - 1010E000)
IMM32.DLL           (76390000 - 763AD000)
MFC80ENU.DLL        (5D360000 - 5D36E000)
comctl32.dll        (773D0000 - 774D3000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
msctfime.ime        (755C0000 - 755EE000)
MacroCore.dll       (00D30000 - 00E31000)
POWRPROF.dll        (74AD0000 - 74AD8000)
WebBrowserSupport.dll(1F900000 - 1F929000)
IMHook.dll          (12300000 - 12308000)
ATL80.DLL           (7C630000 - 7C64B000)
MacroAppSwitch.dll  (10000000 - 10022000)
WTSAPI32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
KhalApi.dll         (01090000 - 010CA000)
LBTServ.dll         (01220000 - 01244000)
kgame.dll           (10E00000 - 10E11000)
GameHook.dll        (10D00000 - 10D0F000)
Apphelp.dll         (77B40000 - 77B62000)
SETUPAPI.dll        (77920000 - 77A13000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
urlmon.dll          (1A400000 - 1A532000)
iertutil.dll        (5DCA0000 - 5DE88000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
Secur32.dll         (77FE0000 - 77FF1000)
LCabHandler.dll     (10A00000 - 10A1F000)
MacroEmail.dll      (10F00000 - 10F32000)
KEMHook.dll         (10300000 - 1030B000)
MacroMedia.dll      (01AB0000 - 01AED000)

PID 1908  - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
MSVCR80.dll         (78130000 - 781CB000)
msvcrt.dll          (77C10000 - 77C68000)
IMM32.DLL           (76390000 - 763AD000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ONINTL.DLL          (33D00000 - 33FC3000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
ole32.dll           (774E0000 - 7761D000)
SAMLIB.dll          (71BF0000 - 71C03000)
msctfime.ime        (755C0000 - 755EE000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)

PID 244   - C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
IMM32.DLL           (76390000 - 763AD000)
KHALAPI.DLL         (10000000 - 1003A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
ole32.dll           (774E0000 - 7761D000)
SAMLIB.dll          (71BF0000 - 71C03000)
msctfime.ime        (755C0000 - 755EE000)
wtsapi32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
LBTServ.dll         (00FE0000 - 01004000)
setupapi.dll        (77920000 - 77A13000)
cfgmgr32.dll        (74AE0000 - 74AE7000)
hid.dll             (688F0000 - 688F9000)
KHALITCH.DLL        (01030000 - 01051000)
KHALMW.DLL          (01080000 - 010A3000)
KHALHPP.DLL         (010E0000 - 01116000)
WINMM.dll           (76B40000 - 76B6D000)
KHALMOU.DLL         (011C0000 - 011E4000)
KHALHID.DLL         (01210000 - 01234000)
KHALUSB.DLL         (01260000 - 01280000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)

PID 200   - C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
mscoree.dll         (79000000 - 79046000)
  mscorlib.dll:_CorDllMain              --[HOOKED]--  @001F4A10 
Cannot read memory @00003A80: 8000000D
  hpqiface.dll:_CorDllMain              --[HOOKED]--  @00003A80 
  system.window_CorDllMain              --[HOOKED]--  @001F3960 
Cannot read memory @00070C60: 8000000D
  system.drawin_CorDllMain              --[HOOKED]--  @00070C60 
  system.dll  :_CorDllMain              --[HOOKED]--  @00128750 
Cannot read memory @0008EAC0: 8000000D
  hpqcc2.dll  :_CorDllMain              --[HOOKED]--  @0008EAC0 
Cannot read memory @000356A0: 8000000D
  hpqutils.dll:_CorDllMain              --[HOOKED]--  @000356A0 
Cannot read memory @000076C0: 8000000D
  hpqfmrsc.dll:_CorDllMain              --[HOOKED]--  @000076C0 
Cannot read memory @00057DF0: 8000000D
  hpqtray.dll :_CorDllMain              --[HOOKED]--  @00057DF0 
Cannot read memory @0000B240: 8000000D
  hpqovskn.dll:_CorDllMain              --[HOOKED]--  @0000B240 
Cannot read memory @0007BA30: 8000000D
  hpqimvlt.dll:_CorDllMain              --[HOOKED]--  @0007BA30 
Cannot read memory @0002C890: 8000000D
  hpqimgrc.dll:_CorDllMain              --[HOOKED]--  @0002C890 
Cannot read memory @0000F510: 8000000D
  hpqntrop.dll:_CorDllMain              --[HOOKED]--  @0000F510 
Cannot read memory @00007770: 8000000D
  interop.hpqcx_CorDllMain              --[HOOKED]--  @00007770 
  system.xml.dl_CorDllMain              --[HOOKED]--  @00145820 
Cannot read memory @00011D80: 8000000D
  lead.dll    :_CorDllMain              --[HOOKED]--  @00011D80 
Cannot read memory @00067590: 8000000D
  lead.wrapper._CorDllMain              --[HOOKED]--  @00067590 
Cannot read memory @00008350: 8000000D
  lead.windows._CorDllMain              --[HOOKED]--  @00008350 
Cannot read memory @00013870: 8000000D
  lead.drawing._CorDllMain              --[HOOKED]--  @00013870 
Cannot read memory @00003F70: 8000000D
  interop.hpqim_CorDllMain              --[HOOKED]--  @00003F70 
Cannot read memory @00004870: 8000000D
  hpqasset.dll:_CorDllMain              --[HOOKED]--  @00004870 
Cannot read memory @0000EA10: 8000000D
  hpqmirsc.dll:_CorDllMain              --[HOOKED]--  @0000EA10 
Cannot read memory @000FAB80: 8000000D
  hpqedit.dll :_CorDllMain              --[HOOKED]--  @000FAB80 
Cannot read memory @00026A80: 8000000D
  hpqvideo.dll:_CorDllMain              --[HOOKED]--  @00026A80 
Cannot read memory @0000F320: 8000000D
  lead.windows._CorDllMain              --[HOOKED]--  @0000F320 
Cannot read memory @0000ED90: 8000000D
  hpqmdmr.dll :_CorDllMain              --[HOOKED]--  @0000ED90 
Cannot read memory @00014200: 8000000D
  lead.drawing._CorDllMain              --[HOOKED]--  @00014200 
Cannot read memory @0000CAB0: 8000000D
  hpqimlib.dll:_CorDllMain              --[HOOKED]--  @0000CAB0 
Cannot read memory @0000F140: 8000000D
  hpqglutl.dll:_CorDllMain              --[HOOKED]--  @0000F140 
Cannot read memory @00005130: 8000000D
  interop.hpqvi_CorDllMain              --[HOOKED]--  @00005130 
Cannot read memory @00003280: 8000000D
  accessibility_CorDllMain              --[HOOKED]--  @00003280 
Cannot read memory @0000C530: 8000000D
  hpqprrsc.dll:_CorDllMain              --[HOOKED]--  @0000C530 
Cannot read memory @000026B0: 8000000D
  interop.hprbl_CorDllMain              --[HOOKED]--  @000026B0 
Cannot read memory @0005BD10: 8000000D
  hpqcprsc.dll:_CorDllMain              --[HOOKED]--  @0005BD10 
Cannot read memory @0000E3A0: 8000000D
  hpqisrtb.dll:_CorDllMain              --[HOOKED]--  @0000E3A0 
Cannot read memory @000BB7D0: 8000000D
  hpqbakup.dll:_CorDllMain              --[HOOKED]--  @000BB7D0 
Cannot read memory @00009E50: 8000000D
  hpqthumb.dll:_CorDllMain              --[HOOKED]--  @00009E50 
KERNEL32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SHLWAPI.dll         (77F60000 - 77FD6000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
msvcrt.dll          (77C10000 - 77C68000)
IMM32.DLL           (76390000 - 763AD000)
mscorwks.dll        (791B0000 - 79419000)
MSVCR71.dll         (7C340000 - 7C396000)
fusion.dll          (00960000 - 009A5000)
ole32.dll           (774E0000 - 7761D000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
mscorlib.dll        (79780000 - 7998E000)
mscorlib.dll        (79990000 - 79CCE000)
mscorsn.dll         (79510000 - 79523000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
hpqiface.dll        (11000000 - 11008000)
system.windows.forms.dll(7B610000 - 7B808000)
system.windows.forms.dll(7B810000 - 7BAF2000)
system.drawing.dll  (7B490000 - 7B506000)
system.drawing.dll  (7B510000 - 7B5DE000)
MSCORJIT.DLL        (79430000 - 7947D000)
system.dll          (7B0A0000 - 7B1D0000)
system.dll          (7B1D0000 - 7B3B4000)
hpqcc2.dll          (02F00000 - 02F94000)
hpqutils.dll        (02FA0000 - 02FDA000)
hpqfmrsc.dll        (02FF0000 - 02FFC000)
hpqtray.dll         (03000000 - 0305C000)
hpqovskn.dll        (03070000 - 03080000)
hpqimvlt.dll        (03080000 - 03100000)
hpqimgrc.dll        (03110000 - 03142000)
xpsp2res.dll        (20000000 - 202C5000)
gdiplus.dll         (4EC50000 - 4EDFB000)
msctfime.ime        (755C0000 - 755EE000)
hpqntrop.dll        (03410000 - 03424000)
interop.hpqcxm08.dll(03530000 - 0353C000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
OLEAUT32.dll        (77120000 - 771AB000)
VERSION.dll         (77C00000 - 77C08000)
hpqcxm08.dll        (14A00000 - 14A23000)
SHFOLDER.dll        (76780000 - 76789000)
MSVCP60.dll         (76080000 - 760E5000)
system.xml.dll      (7BC10000 - 7BD5A000)
system.xml.dll      (7BD60000 - 7BF62000)
lead.dll            (03580000 - 03596000)
lead.wrapper.dll    (035A0000 - 0360C000)
ltkrn13n.dll        (03620000 - 03694000)
lead.windows.forms.dll(03AB0000 - 03ABE000)
lead.drawing.dll    (040E0000 - 040F8000)
interop.hpqimgr.dll (04110000 - 04118000)
msi.dll             (7D1E0000 - 7D49E000)
SXS.DLL             (75E90000 - 75F40000)
hpqimgr.dll         (10000000 - 10077000)
MFC71.DLL           (7C140000 - 7C243000)
ATL71.DLL           (7C120000 - 7C139000)
MSVCP71.dll         (7C3A0000 - 7C41B000)
MFC71ENU.DLL        (5D360000 - 5D36E000)
hpqasset.dll        (04330000 - 0433A000)
hpqmirsc.dll        (043F0000 - 04404000)
hpqedit.dll         (04410000 - 04510000)
hpqvideo.dll        (04510000 - 0453C000)
lead.windows.forms.drawingcontainer.dll(04550000 - 04564000)
hpqmdmr.dll         (04580000 - 04594000)
lead.drawing.imaging.imageprocessing.dll(045A0000 - 045BA000)
hpqimlib.dll        (045C0000 - 045D2000)
hpqglutl.dll        (045E0000 - 045F4000)
psapi.dll           (76BF0000 - 76BFB000)
interop.hpqvideo.dll(04620000 - 0462A000)
hpqvdcom.dll        (04670000 - 046A2000)
WINMM.dll           (76B40000 - 76B6D000)
accessibility.dll   (79E40000 - 79E48000)
hpqprrsc.dll        (047A0000 - 047B2000)
interop.hprblog.dll (04AF0000 - 04AF8000)
hpqcprsc.dll        (04D10000 - 04D70000)
hpqisrtb.dll        (04D70000 - 04D84000)
hpqbakup.dll        (04D90000 - 04E50000)
hpqthumb.dll        (04E50000 - 04E5E000)

PID 776   - C:\Program Files\Bonjour\mDNSResponder.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
WS2_32.dll          (71AB0000 - 71AC7000)
msvcrt.dll          (77C10000 - 77C68000)
WS2HELP.dll         (71AA0000 - 71AA8000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
IPHLPAPI.DLL        (76D60000 - 76D79000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
IMM32.DLL           (76390000 - 763AD000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
MPRAPI.dll          (76D40000 - 76D58000)
ACTIVEDS.dll        (77CC0000 - 77CF2000)
adsldpc.dll         (76E10000 - 76E35000)
NETAPI32.dll        (5B860000 - 5B8B4000)
WLDAP32.dll         (76F60000 - 76F8C000)
ATL.DLL             (76B20000 - 76B31000)
rtutils.dll         (76E80000 - 76E8E000)
SAMLIB.dll          (71BF0000 - 71C03000)
SETUPAPI.dll        (77920000 - 77A13000)

PID 2124  - C:\Program Files\Java\jre6\bin\jqs.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
WS2_32.dll          (71AB0000 - 71AC7000)
msvcrt.dll          (77C10000 - 77C68000)
WS2HELP.dll         (71AA0000 - 71AA8000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ole32.dll           (774E0000 - 7761D000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
MSVCR71.dll         (7C340000 - 7C396000)
IMM32.DLL           (76390000 - 763AD000)
psapi.dll           (76BF0000 - 76BFB000)
pdh.dll             (74000000 - 74056000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
ODBC32.dll          (74320000 - 7435D000)
odbcbcp.dll         (711A0000 - 711A6000)
VERSION.dll         (77C00000 - 77C08000)
OLEAUT32.dll        (77120000 - 771AB000)
comctl32.dll        (773D0000 - 774D3000)
odbcint.dll         (20000000 - 20017000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
perfos.dll          (5E760000 - 5E76A000)
perfdisk.dll        (5E790000 - 5E799000)

PID 2188  - C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ole32.dll           (774E0000 - 7761D000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
VERSION.dll         (77C00000 - 77C08000)
SHLWAPI.dll         (77F60000 - 77FD6000)
IMM32.DLL           (76390000 - 763AD000)
psapi.dll           (76BF0000 - 76BFB000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
csm.dll             (54A30000 - 54A51000)
msdbg2.dll          (3F0E0000 - 3F122000)

PID 2308  - C:\WINDOWS\system32\HPZipm12.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
msvcrt.dll          (77C10000 - 77C68000)
WS2HELP.dll         (71AA0000 - 71AA8000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
IMM32.DLL           (76390000 - 763AD000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
ole32.dll           (774E0000 - 7761D000)
SAMLIB.dll          (71BF0000 - 71C03000)
uxtheme.dll         (5AD70000 - 5ADA8000)

PID 2408  - C:\WINDOWS\System32\svchost.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
WINMM.dll           (76B40000 - 76B6D000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
wiaservc.dll        (75AA0000 - 75AF5000)
CFGMGR32.dll        (74AE0000 - 74AE7000)
setupapi.dll        (77920000 - 77A13000)
mscms.dll           (73B30000 - 73B45000)
WINSPOOL.DRV        (73000000 - 73026000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
actxprxy.dll        (71D40000 - 71D5C000)

PID 2500  - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe for checking.
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll for checking.
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
 [i] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll for checking.
GDI32.dll           (77F10000 - 77F58000)
VERSION.dll         (77C00000 - 77C08000)
ole32.dll           (774E0000 - 7761D000)
msvcrt.dll          (77C10000 - 77C68000)
OLEAUT32.dll        (77120000 - 771AB000)
SHLWAPI.dll         (77F60000 - 77FD6000)
IMM32.DLL           (76390000 - 763AD000)
symlcnet.dll        (20000000 - 20057000)
[-] Unable to load module C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcnet.dll for checking
MSVCR71.DLL         (7C340000 - 7C396000)
xpsp2res.dll        (00D80000 - 01045000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
msi.dll             (7D1E0000 - 7D49E000)
SXS.DLL             (75E90000 - 75F40000)

PID 2528  - C:\Program Files\Viewpoint\Common\ViewpointService.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
ATL.DLL             (76B20000 - 76B31000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
uxtheme.dll         (5AD70000 - 5ADA8000)
xpsp2res.dll        (20000000 - 202C5000)

PID 4076  - C:\Program Files\iPod\bin\iPodService.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
CFGMGR32.dll        (74AE0000 - 74AE7000)
setupapi.dll        (77920000 - 77A13000)
msvcrt.dll          (77C10000 - 77C68000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
GDI32.dll           (77F10000 - 77F58000)
USER32.dll          (7E410000 - 7E4A0000)
VERSION.dll         (77C00000 - 77C08000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
IMM32.DLL           (76390000 - 763AD000)
iPodServiceLocalized.DLL(10000000 - 1000E000)
iPodService.DLL     (00890000 - 0089E000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
uxtheme.dll         (5AD70000 - 5ADA8000)
Wtsapi32.dll        (76F50000 - 76F58000)
WINSTA.dll          (76360000 - 76370000)
NETAPI32.dll        (5B860000 - 5B8B4000)
msi.dll             (7D1E0000 - 7D49E000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
SXS.DLL             (75E90000 - 75F40000)

PID 2692  - C:\WINDOWS\System32\alg.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
msvcrt.dll          (77C10000 - 77C68000)
ATL.DLL             (76B20000 - 76B31000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
MSWSOCK.DLL         (71A50000 - 71A8F000)
ShimEng.dll         (5CB70000 - 5CB96000)
AcGenral.DLL        (6F880000 - 6FA4A000)
WINMM.dll           (76B40000 - 76B6D000)
MSACM32.dll         (77BE0000 - 77BF5000)
VERSION.dll         (77C00000 - 77C08000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
SHLWAPI.dll         (77F60000 - 77FD6000)
USERENV.dll         (769C0000 - 76A73000)
UxTheme.dll         (5AD70000 - 5ADA8000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
xpsp2res.dll        (20000000 - 202C5000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)

PID 3876  - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
WSOCK32.dll         (71AD0000 - 71AD9000)
WS2_32.dll          (71AB0000 - 71AC7000)
msvcrt.dll          (77C10000 - 77C68000)
WS2HELP.dll         (71AA0000 - 71AA8000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
ole32.dll           (774E0000 - 7761D000)
OLEAUT32.dll        (77120000 - 771AB000)
SHLWAPI.dll         (77F60000 - 77FD6000)
MSVCP71.dll         (7C3A0000 - 7C41B000)
MSVCR71.dll         (7C340000 - 7C396000)
IMM32.DLL           (76390000 - 763AD000)
uxtheme.dll         (5AD70000 - 5ADA8000)
comctl32.dll        (773D0000 - 774D3000)
comctl32.dll        (5D090000 - 5D12A000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
VERSION.dll         (77C00000 - 77C08000)
DNSAPI.dll          (76F20000 - 76F47000)
rasadhlp.dll        (76FC0000 - 76FC6000)

PID 3332  - C:\Program Files\Internet Explorer\IEXPLORE.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
The code of CreateWindowExW at 7E41FC25 (0) got patched. Here is the diff:
Address   New-Original
7E41FC25: E9 - 8B  
7E41FC26: 08 - FF  
7E41FC27: 4C - 55  
7E41FC28: E2 - 8B  
7E41FC29: 82 - EC  
--> JMP DWORD PTR DS:[01244832]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxIndirectParamA at 7E456B50 (0) got patched. Here is the diff:
Address   New-Original
7E456B50: E9 - 8B  
7E456B51: 2F - FF  
7E456B52: 75 - 55  
7E456B53: F0 - 8B  
7E456B54: 82 - EC  
--> JMP DWORD PTR DS:[0135E084]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxIndirectParamW at 7E432032 (0) got patched. Here is the diff:
Address   New-Original
7E432032: E9 - 8B  
7E432033: EA - FF  
7E432034: BF - 55  
7E432035: F2 - 8B  
7E432036: 82 - EC  
--> JMP DWORD PTR DS:[0135E021]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxParamA at 7E43B10C (0) got patched. Here is the diff:
Address   New-Original
7E43B10C: E9 - 8B  
7E43B10D: AD - FF  
7E43B10E: 2E - 55  
7E43B10F: F2 - 8B  
7E43B110: 82 - EC  
--> JMP DWORD PTR DS:[0135DFBE]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxParamW at 7E42555F (0) got patched. Here is the diff:
Address   New-Original
7E42555F: E9 - 8B  
7E425560: B1 - FF  
7E425561: 3D - 55  
7E425562: D4 - 8B  
7E425563: 82 - EC  
--> JMP DWORD PTR DS:[01169315]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxExA at 7E4505FC (0) got patched. Here is the diff:
Address   New-Original
7E4505FC: E9 - 8B  
7E4505FD: 83 - FF  
7E4505FE: D8 - 55  
7E4505FF: F0 - 8B  
7E450600: 82 - EC  
--> JMP DWORD PTR DS:[0135DE84]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxExW at 7E4505D8 (0) got patched. Here is the diff:
Address   New-Original
7E4505D8: E9 - 8B  
7E4505D9: 45 - FF  
7E4505DA: D8 - 55  
7E4505DB: F0 - 8B  
7E4505DC: 82 - EC  
--> JMP DWORD PTR DS:[0135DE22]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxIndirectA at 7E43A04A (0) got patched. Here is the diff:
Address   New-Original
7E43A04A: E9 - 8B  
7E43A04B: 02 - FF  
7E43A04C: 3F - 55  
7E43A04D: F2 - 8B  
7E43A04E: 82 - EC  
--> JMP DWORD PTR DS:[0135DF51]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxIndirectW at 7E4662AB (0) got patched. Here is the diff:
Address   New-Original
7E4662AB: E9 - 8B  
7E4662AC: 36 - FF  
7E4662AD: 7C - 55  
7E4662AE: EF - 8B  
7E4662AF: 82 - EC  
--> JMP DWORD PTR DS:[0135DEE6]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
GDI32.dll           (77F10000 - 77F58000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ole32.dll           (774E0000 - 7761D000)
iertutil.dll        (5DCA0000 - 5DE88000)
urlmon.dll          (1A400000 - 1A532000)
OLEAUT32.dll        (77120000 - 771AB000)
The code of OleCreatePropertyFrameIndirect at 77187C74 (0) got patched. Here is the diff:
Address   New-Original
77187C74: E9 - 8B  
77187C75: 38 - FF  
77187C76: 6C - 55  
77187C77: 1D - 8B  
77187C78: 8A - EC  
--> JMP DWORD PTR DS:[0135E8B1]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
The code of PropertySheet at 773DCF4D (0) got patched. Here is the diff:
Address   New-Original
773DCF4D: E9 - 8B  
773DCF4E: CD - FF  
773DCF4F: 21 - 55  
773DCF50: F8 - 8B  
773DCF51: 89 - EC  
--> JMP DWORD PTR DS:[0135F11F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of PropertySheetA at 773DCF4D (0) got patched. Here is the diff:
Address   New-Original
773DCF4D: E9 - 8B  
773DCF4E: CD - FF  
773DCF4F: 21 - 55  
773DCF50: F8 - 8B  
773DCF51: 89 - EC  
--> JMP DWORD PTR DS:[0135F11F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of PropertySheetW at 773DCF35 (0) got patched. Here is the diff:
Address   New-Original
773DCF35: E9 - 8B  
773DCF36: 45 - FF  
773DCF37: 21 - 55  
773DCF38: F8 - 8B  
773DCF39: 89 - EC  
--> JMP DWORD PTR DS:[0135F07F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
comctl32.dll        (5D090000 - 5D12A000)
IEFRAME.dll         (01110000 - 01BA1000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (00920000 - 00929000)
Secur32.dll         (77FE0000 - 77FF1000)
ws2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
VERSION.dll         (77C00000 - 77C08000)
comdlg32.dll        (763B0000 - 763F9000)
The code of PageSetupDlgW at 763D48D6 (0) got patched. Here is the diff:
Address   New-Original
763D48D6: E9 - 8B  
763D48D7: 08 - FF  
763D48D8: A1 - 55  
763D48D9: F8 - 8B  
763D48DA: 8A - EC  
--> JMP DWORD PTR DS:[0135E9E3]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
uxtheme.dll         (5AD70000 - 5ADA8000)
mswsock.dll         (71A50000 - 71A8F000)
DNSAPI.dll          (76F20000 - 76F47000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
mdnsNSP.dll         (16080000 - 160A5000)
xpsp2res.dll        (20000000 - 202C5000)
Iphlpapi.dll        (76D60000 - 76D79000)
rasadhlp.dll        (76FC0000 - 76FC6000)
RASAPI32.dll        (76EE0000 - 76F1C000)
rasman.dll          (76E90000 - 76EA2000)
NETAPI32.dll        (5B860000 - 5B8B4000)
TAPI32.dll          (76EB0000 - 76EDF000)
rtutils.dll         (76E80000 - 76E8E000)
WINMM.dll           (76B40000 - 76B6D000)
USERENV.dll         (769C0000 - 76A73000)
sensapi.dll         (722B0000 - 722B5000)
msv1_0.dll          (77C70000 - 77C94000)
cryptdll.dll        (76790000 - 7679C000)
msctfime.ime        (755C0000 - 755EE000)
IEUI.dll            (021F0000 - 0221A000)
MSIMG32.dll         (76380000 - 76385000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
ieproxy.dll         (02620000 - 02660000)
msimtf.dll          (746F0000 - 7471A000)
appHelp.dll         (77B40000 - 77B62000)
GrooveShellExtensions.dll(661D0000 - 663EF000)
GrooveUtil.DLL      (68EF0000 - 68FE2000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
GrooveNew.DLL       (68FF0000 - 68FF7000)
ATL80.DLL           (7C630000 - 7C64B000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
SETUPAPI.dll        (77920000 - 77A13000)
oleacc.dll          (74C80000 - 74CAC000)
MSVCP60.dll         (76080000 - 760E5000)
xmllite.dll         (47060000 - 47081000)
msi.dll             (7D1E0000 - 7D49E000)
SXS.DLL             (75E90000 - 75F40000)
actxprxy.dll        (71D40000 - 71D5C000)
MLANG.dll           (75CF0000 - 75D81000)
USP10.dll           (74D90000 - 74DFB000)

PID 1156  - C:\Program Files\Internet Explorer\IEXPLORE.EXE
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
  ole32.dll   :LoadLibraryExW           --[HOOKED]--  @009318FD by C:\Program Files\Internet Explorer\xpshims.dll

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\Program Files\Internet Explorer\xpshims.dll:
Base address:	00930000
Size:		00006000
Flags:		80284004
Load count:	1
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer Compatibility Shims for XP
Location:	C:\Program Files\Internet Explorer\xpshims.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
USER32.dll          (7E410000 - 7E4A0000)
The code of CallNextHookEx at 7E41F85B (0) got patched. Here is the diff:
Address   New-Original
7E41F85B: E9 - 8B  
7E41F85C: 21 - FF  
7E41F85D: E5 - 55  
7E41F85E: E1 - 8B  
7E41F85F: 82 - EC  
--> JMP DWORD PTR DS:[0123DD81]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of CreateWindowExW at 7E41FC25 (0) got patched. Here is the diff:
Address   New-Original
7E41FC25: E9 - 8B  
7E41FC26: 08 - FF  
7E41FC27: 4C - 55  
7E41FC28: E2 - 8B  
7E41FC29: 82 - EC  
--> JMP DWORD PTR DS:[01244832]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxIndirectParamA at 7E456B50 (0) got patched. Here is the diff:
Address   New-Original
7E456B50: E9 - 8B  
7E456B51: 2F - FF  
7E456B52: 75 - 55  
7E456B53: F0 - 8B  
7E456B54: 82 - EC  
--> JMP DWORD PTR DS:[0135E084]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxIndirectParamW at 7E432032 (0) got patched. Here is the diff:
Address   New-Original
7E432032: E9 - 8B  
7E432033: EA - FF  
7E432034: BF - 55  
7E432035: F2 - 8B  
7E432036: 82 - EC  
--> JMP DWORD PTR DS:[0135E021]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxParamA at 7E43B10C (0) got patched. Here is the diff:
Address   New-Original
7E43B10C: E9 - 8B  
7E43B10D: AD - FF  
7E43B10E: 2E - 55  
7E43B10F: F2 - 8B  
7E43B110: 82 - EC  
--> JMP DWORD PTR DS:[0135DFBE]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of DialogBoxParamW at 7E42555F (0) got patched. Here is the diff:
Address   New-Original
7E42555F: E9 - 8B  
7E425560: B1 - FF  
7E425561: 3D - 55  
7E425562: D4 - 8B  
7E425563: 82 - EC  
--> JMP DWORD PTR DS:[01169315]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxExA at 7E4505FC (0) got patched. Here is the diff:
Address   New-Original
7E4505FC: E9 - 8B  
7E4505FD: 83 - FF  
7E4505FE: D8 - 55  
7E4505FF: F0 - 8B  
7E450600: 82 - EC  
--> JMP DWORD PTR DS:[0135DE84]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxExW at 7E4505D8 (0) got patched. Here is the diff:
Address   New-Original
7E4505D8: E9 - 8B  
7E4505D9: 45 - FF  
7E4505DA: D8 - 55  
7E4505DB: F0 - 8B  
7E4505DC: 82 - EC  
--> JMP DWORD PTR DS:[0135DE22]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxIndirectA at 7E43A04A (0) got patched. Here is the diff:
Address   New-Original
7E43A04A: E9 - 8B  
7E43A04B: 02 - FF  
7E43A04C: 3F - 55  
7E43A04D: F2 - 8B  
7E43A04E: 82 - EC  
--> JMP DWORD PTR DS:[0135DF51]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of MessageBoxIndirectW at 7E4662AB (0) got patched. Here is the diff:
Address   New-Original
7E4662AB: E9 - 8B  
7E4662AC: 36 - FF  
7E4662AD: 7C - 55  
7E4662AE: EF - 8B  
7E4662AF: 82 - EC  
--> JMP DWORD PTR DS:[0135DEE6]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of SetWindowsHookExW at 7E42DDB5 (0) got patched. Here is the diff:
Address   New-Original
7E42DDB5: E9 - 8B  
7E42DDB6: 11 - FF  
7E42DDB7: FE - 55  
7E42DDB8: E0 - 8B  
7E42DDB9: 82 - EC  
--> JMP DWORD PTR DS:[0123DBCB]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of UnhookWindowsHookEx at 7E41F21E (0) got patched. Here is the diff:
Address   New-Original
7E41F21E: E9 - B8  
7E41F21F: 7F - 3A  
7E41F220: 2A - 12  
7E41F221: D8 - 00  
7E41F222: 82 - 00  
--> JMP DWORD PTR DS:[011A1CA2]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
GDI32.dll           (77F10000 - 77F58000)
msvcrt.dll          (77C10000 - 77C68000)
SHLWAPI.dll         (77F60000 - 77FD6000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ole32.dll           (774E0000 - 7761D000)
The code of CoCreateInstance at 774FFAC3 (0) got patched. Here is the diff:
Address   New-Original
774FFAC3: E9 - 8B  
774FFAC4: C6 - FF  
774FFAC5: 4D - 55  
774FFAC6: D4 - 8B  
774FFAC7: 89 - EC  
--> JMP DWORD PTR DS:[0124488E]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
iertutil.dll        (5DCA0000 - 5DE88000)
urlmon.dll          (1A400000 - 1A532000)
OLEAUT32.dll        (77120000 - 771AB000)
The code of OleCreatePropertyFrameIndirect at 77187C74 (0) got patched. Here is the diff:
Address   New-Original
77187C74: E9 - 8B  
77187C75: 38 - FF  
77187C76: 6C - 55  
77187C77: 1D - 8B  
77187C78: 8A - EC  
--> JMP DWORD PTR DS:[0135E8B1]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
The code of PropertySheet at 773DCF4D (0) got patched. Here is the diff:
Address   New-Original
773DCF4D: E9 - 8B  
773DCF4E: CD - FF  
773DCF4F: 21 - 55  
773DCF50: F8 - 8B  
773DCF51: 89 - EC  
--> JMP DWORD PTR DS:[0135F11F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of PropertySheetA at 773DCF4D (0) got patched. Here is the diff:
Address   New-Original
773DCF4D: E9 - 8B  
773DCF4E: CD - FF  
773DCF4F: 21 - 55  
773DCF50: F8 - 8B  
773DCF51: 89 - EC  
--> JMP DWORD PTR DS:[0135F11F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
The code of PropertySheetW at 773DCF35 (0) got patched. Here is the diff:
Address   New-Original
773DCF35: E9 - 8B  
773DCF36: 45 - FF  
773DCF37: 21 - 55  
773DCF38: F8 - 8B  
773DCF39: 89 - EC  
--> JMP DWORD PTR DS:[0135F07F]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
comctl32.dll        (5D090000 - 5D12A000)
IEFRAME.dll         (01110000 - 01BA1000)
comdlg32.dll        (763B0000 - 763F9000)
The code of PageSetupDlgW at 763D48D6 (0) got patched. Here is the diff:
Address   New-Original
763D48D6: E9 - 8B  
763D48D7: 08 - FF  
763D48D8: A1 - 55  
763D48D9: F8 - 8B  
763D48DA: 8A - EC  
--> JMP DWORD PTR DS:[0135E9E3]
Patched by C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15

:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
Information about C:\WINDOWS\system32\IEFRAME.dll!ImportCookieFileByProcessW+0xFEBFDC15:
Base address:	01110000
Size:		00A91000
Flags:		802C4004
Load count:	3
Name:		Windows Internet Explorer
Prod. Version:	8.00.6001.18702
Company:	Microsoft Corporation
File Version:	8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
Description:	Internet Explorer
Location:	C:\WINDOWS\system32\IEFRAME.dll
Signed:		YES
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::
xpshims.dll         (00930000 - 00936000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
xpsp2res.dll        (20000000 - 202C5000)
CLBCATQ.DLL         (76FD0000 - 7704F000)
COMRes.dll          (77050000 - 77115000)
VERSION.dll         (77C00000 - 77C08000)
ieproxy.dll         (022B0000 - 022F0000)
WININET.dll         (63000000 - 630E6000)
Normaliz.dll        (023F0000 - 023F9000)
SETUPAPI.dll        (77920000 - 77A13000)
Secur32.dll         (77FE0000 - 77FF1000)
ws2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
MLANG.dll           (75CF0000 - 75D81000)
msctfime.ime        (755C0000 - 755EE000)
msi.dll             (7D1E0000 - 7D49E000)
SXS.DLL             (75E90000 - 75F40000)
actxprxy.dll        (71D40000 - 71D5C000)
mshtml.dll          (63580000 - 63B2C000)
msls31.dll          (02810000 - 02839000)
appHelp.dll         (77B40000 - 77B62000)
PSAPI.DLL           (76BF0000 - 76BFB000)
RASAPI32.dll        (76EE0000 - 76F1C000)
rasman.dll          (76E90000 - 76EA2000)
NETAPI32.dll        (5B860000 - 5B8B4000)
TAPI32.dll          (76EB0000 - 76EDF000)
rtutils.dll         (76E80000 - 76E8E000)
WINMM.dll           (76B40000 - 76B6D000)
USERENV.dll         (769C0000 - 76A73000)
sensapi.dll         (722B0000 - 722B5000)
msv1_0.dll          (77C70000 - 77C94000)
cryptdll.dll        (76790000 - 7679C000)
iphlpapi.dll        (76D60000 - 76D79000)
msimtf.dll          (746F0000 - 7471A000)
OLEACC.dll          (74C80000 - 74CAC000)
MSVCP60.dll         (76080000 - 760E5000)
PPBHO.dll           (02BF0000 - 02C3A000)
msxml4.dll          (69B10000 - 69C5D000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
rasadhlp.dll        (76FC0000 - 76FC6000)
DNSAPI.dll          (76F20000 - 76F47000)
mdnsNSP.dll         (16080000 - 160A5000)
iepeers.dll         (03980000 - 039AF000)
WINSPOOL.DRV        (73000000 - 73026000)
scrchpg.dll         (6D930000 - 6D955000)
jscript.dll         (63380000 - 63434000)
klscav.dll          (6D4F0000 - 6D4FA000)
prremote.dll        (6D900000 - 6D916000)
MSVCP80.dll         (7C420000 - 7C4A7000)
prloader.dll        (6D8D0000 - 6D8F7000)
params.ppl          (6E3D0000 - 6E47B000)
pxstub.ppl          (6E6A0000 - 6E6A9000)
ImgUtil.dll         (1B000000 - 1B00C000)
pngfilt.dll         (1B060000 - 1B06E000)
msimg32.dll         (76380000 - 76385000)
USP10.dll           (74D90000 - 74DFB000)
msxml3.dll          (74980000 - 74AA3000)
PPUI.DLL            (10000000 - 100BD000)
MFC70.DLL           (7C140000 - 7C22E000)
MSVCR70.dll         (7C000000 - 7C054000)
MSVCP70.dll         (7C080000 - 7C0F7000)
RICHED20.DLL        (74E30000 - 74E9C000)
GDIPLUS.DLL         (70D00000 - 70EA0000)
PPRES.DLL           (04D80000 - 04DD5000)
[-] Unable to load module C:\Program Files\Norton Password Manager\PPRES.DLL for checking
gdiplus.dll         (4EC50000 - 4EDFB000)
PPW32EVT.dll        (04F00000 - 04F0A000)
wdmaud.drv          (72D20000 - 72D29000)
WINTRUST.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
msacm32.drv         (72D10000 - 72D18000)
MSACM32.dll         (77BE0000 - 77BF5000)
midimap.dll         (77BD0000 - 77BD7000)
MSRATING.dll        (055A0000 - 055D3000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
GrooveShellExtensions.dll(05850000 - 05A6F000)
GrooveUtil.DLL      (68EF0000 - 68FE2000)
GrooveNew.DLL       (68FF0000 - 68FF7000)
ATL80.DLL           (7C630000 - 7C64B000)
ntshrui.dll         (76990000 - 769B5000)
ATL.DLL             (76B20000 - 76B31000)
LINKINFO.dll        (76980000 - 76988000)
GrooveSystemServices.dll(65E50000 - 65E7D000)
wuapi.dll           (506A0000 - 5072E000)
Cabinet.dll         (75150000 - 75164000)

PID 3544  - C:\Documents and Settings\John\Desktop\radixgui.exe
-------------------------------------------------------------------------------
ntdll.dll           (7C900000 - 7C9B2000)
kernel32.dll        (7C800000 - 7C8F5000)
USER32.dll          (7E410000 - 7E4A0000)
GDI32.dll           (77F10000 - 77F58000)
comdlg32.dll        (763B0000 - 763F9000)
SHLWAPI.dll         (77F60000 - 77FD6000)
ADVAPI32.dll        (77DD0000 - 77E6B000)
RPCRT4.dll          (77E70000 - 77F01000)
msvcrt.dll          (77C10000 - 77C68000)
COMCTL32.dll        (5D090000 - 5D12A000)
SHELL32.dll         (7C9C0000 - 7D1D7000)
ole32.dll           (774E0000 - 7761D000)
VERSION.dll         (77C00000 - 77C08000)
dbghelp.dll         (59A60000 - 59B01000)
IMM32.DLL           (76390000 - 763AD000)
comctl32.dll        (773D0000 - 774D3000)
wintrust.dll        (76C30000 - 76C5E000)
CRYPT32.dll         (77A80000 - 77B14000)
MSASN1.dll          (77B20000 - 77B32000)
IMAGEHLP.dll        (76C90000 - 76CB8000)
NTMARTA.DLL         (77690000 - 776B1000)
WLDAP32.dll         (76F60000 - 76F8C000)
SAMLIB.dll          (71BF0000 - 71C03000)
Secur32.dll         (77FE0000 - 77FF1000)
uxtheme.dll         (5AD70000 - 5ADA8000)
MSCTF.dll           (74720000 - 7476B000)
lgscroll.dll        (10100000 - 1010E000)
MSVCR80.dll         (78130000 - 781CB000)
msctfime.ime        (755C0000 - 755EE000)
OLEAUT32.DLL        (77120000 - 771AB000)
xpsp2res.dll        (20000000 - 202C5000)
rsaenh.dll          (0FFD0000 - 0FFF8000)
userenv.dll         (769C0000 - 76A73000)
netapi32.dll        (5B860000 - 5B8B4000)
cryptnet.dll        (75E60000 - 75E73000)
WINHTTP.dll         (4D4F0000 - 4D548000)
SensApi.dll         (722B0000 - 722B5000)
Cabinet.dll         (75150000 - 75164000)
ws2_32.dll          (71AB0000 - 71AC7000)
WS2HELP.dll         (71AA0000 - 71AA8000)
mswsock.dll         (71A50000 - 71A8F000)
hnetcfg.dll         (662B0000 - 66308000)
wshtcpip.dll        (71A90000 - 71A98000)
RASAPI32.DLL        (76EE0000 - 76F1C000)
rasman.dll          (76E90000 - 76EA2000)
TAPI32.dll          (76EB0000 - 76EDF000)
rtutils.dll         (76E80000 - 76E8E000)
WINMM.dll           (76B40000 - 76B6D000)
msv1_0.dll          (77C70000 - 77C94000)
cryptdll.dll        (76790000 - 7679C000)
iphlpapi.dll        (76D60000 - 76D79000)
DNSAPI.dll          (76F20000 - 76F47000)
mdnsNSP.dll         (16080000 - 160A5000)
rasadhlp.dll        (76FC0000 - 76FC6000)
---- Check ended at 17.4.2010 1:28:55 ----
 